What is CVE-2026-53792?
This vulnerability in rsync versions before 3.5.0 involves an out-of-bounds read in the sender-side block matching logic. A malicious receiver can exploit this by sending a crafted checksum block with zero length, triggering memory access before the allocated buffer. Upgrading rsync to the latest version is recommended to mitigate the issue.
Azərbaycanca: Bu zəiflik rsync-in 3.5.0 versiyasından əvvəlki versiyalarında "sender-side block matching" məntiqində "out-of-bounds read" probleminə səbəb olur. Təcavüzkar xüsusi hazırlanmış boş uzunluqlu "checksum block" göndərərək yaddaşa icazəsiz oxuma həyata keçirə bilər. Təsirə məruz qalmamaq üçün rsync-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which software is affected by CVE-2026-53792?
CVE-2026-53792 affects versions of rsync prior to 3.5.0.
How can I protect against CVE-2026-53792?
Upgrading rsync to the latest version is recommended to prevent the exploitation of this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.