CVE-2026-70459
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
13/08/2026
Last modified:
31/08/2026
Description
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.5.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



