Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. | |
| Title | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:44:56.646Z
Reserved: 2026-08-04T14:52:23.814Z
Link: CVE-2026-70456
No data.
Status : Received
Published: 2026-08-13T15:19:59.343
Modified: 2026-08-13T15:19:59.343
Link: CVE-2026-70456
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z