Skip to content

GHSA-cg57-rp9g-56hw on CTRL-OS 26.05

Aliases: GHSA-cg57-rp9g-56hw, CVE-2026-53792

Packages: rsync

Status: Plausible

Advisory Information

A malicious receiver sending a checksum header with count > 0 and block length == 0 made the sender's rolling-match arithmetic compute a negative offset.

Fix: reject a checksum header with a zero block length.

Test: checksum-zero-blocklen.

Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)

Updates

2026-08-14 16:57 CEST

Metadata changes:

  • Status for package rsync: “Plausible

2026-08-14 16:55 CEST

Metadata changes:

  • Status for package rsync: “New