Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2803 articles · 111233 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE

UAF in rsync 3.4.1 and below

56% confidence

Description

The receive_xattr() function in rsync uses a wire-supplied count value for qsort() that may exceed the number of valid items after xattr filtering. This leads to use-after-free conditions when stale array entries are processed, causing double-free or free-of-allocated-memory scenarios during xattr handling.

Affected Products

VendorProductVersions
—rsync3.0.1 - 3.4.1

Related News (1 articles)

Tier C
oss-security3h ago
UAF in rsync 3.4.1 and below
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-416
PublishedApr 16, 2026
Last enriched2h ago
Tags
use-after-freersyncxattr
Trending Score27
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, vendor, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Apr 16, 2026
Discovered by ZDM
Apr 16, 2026