VulnerabilityModified
CVE-2026-41035
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free.
HIGH 7.8EPSS 0.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-130, CWE-805
- Affected
- samba/rsync
- Source
- cve@mitre.org
References
- https://github.com/RsyncProject/rsync/issues/871Issue Tracking
- https://github.com/RsyncProject/rsync/releasesRelease Notes
- https://www.openwall.com/lists/oss-security/2026/04/16/2Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/04/16/9Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/04/22/3Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:17481
- https://access.redhat.com/errata/RHSA-2026:19152
- https://access.redhat.com/errata/RHSA-2026:19368
- https://access.redhat.com/errata/RHSA-2026:20601
- https://access.redhat.com/errata/RHSA-2026:20602
- https://access.redhat.com/errata/RHSA-2026:20603
- https://access.redhat.com/errata/RHSA-2026:20604
- https://access.redhat.com/errata/RHSA-2026:20696
- https://access.redhat.com/errata/RHSA-2026:23233
- https://access.redhat.com/errata/RHSA-2026:23245
- https://access.redhat.com/errata/RHSA-2026:25044
- https://access.redhat.com/errata/RHSA-2026:25149
- https://access.redhat.com/errata/RHSA-2026:25170
- https://access.redhat.com/errata/RHSA-2026:25172
- https://access.redhat.com/errata/RHSA-2026:25173
- https://access.redhat.com/errata/RHSA-2026:25181
- https://access.redhat.com/errata/RHSA-2026:25190
- https://access.redhat.com/errata/RHSA-2026:26542
- https://access.redhat.com/errata/RHSA-2026:28887
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:34098
- https://access.redhat.com/errata/RHSA-2026:59831
- https://access.redhat.com/security/cve/CVE-2026-41035
- https://bugzilla.redhat.com/show_bug.cgi?id=2458898
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41035.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.