CVE-2025-10158
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/11/2025
Last modified:
19/11/2025
Description
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The <br />
<br />
malicious <br />
<br />
rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



