Bug 2415637 (CVE-2025-10158) - CVE-2025-10158 rsync: Rsync: Out of bounds array access via negative index
Summary: CVE-2025-10158 rsync: Rsync: Out of bounds array access via negative index
Keywords:
Status: NEW
Alias: CVE-2025-10158
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2415718 2415719 2415720
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-18 15:01 UTC by OSIDB Bzimport
Modified: 2025-11-18 19:20 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-18 15:01:37 UTC
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The 

malicious 

rsync client requires at least read access to the remote rsync module in order to trigger the issue.


Note You need to log in before you can comment on or make changes to this bug.