GHSA-cg57-rp9g-56hw on CTRL-OS 26.05
Aliases: GHSA-cg57-rp9g-56hw, CVE-2026-53792
Packages: rsync
Status: Plausible
Advisory Information
A malicious receiver sending a checksum header with count > 0 and block length == 0 made the sender's rolling-match arithmetic compute a negative offset.
Fix: reject a checksum header with a zero block length.
Test: checksum-zero-blocklen.
Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)
Updates
2026-08-14 16:57 CEST
Metadata changes:
- Status for package
rsync: “Plausible”
2026-08-14 16:55 CEST
Metadata changes:
- Status for package
rsync: “New”