What is CVE-2026-53794?
A logic error in rsync before version 3.5.0 in the handling of the --max-alloc option allows a sender or configuration to set --max-alloc=0, completely disabling allocation sanity checks instead of enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations, and users should immediately update to rsync version 3.5.0 or later.
Azərbaycanca: rsync 3.5.0 versiyasından əvvəlki proqramlarda --max-alloc parametrinin idarə edilməsində məntiq xətası aşkarlanıb. Bu boşluq göndərən tərəfə və ya konfiqurasiyaya --max-alloc=0 təyin edərək yaddaş yoxlamalarını tamamilə söndürməyə imkan verir. Nəticədə hücumçu qəbul edən tərəfdə nəzarətsiz yaddaş ayrılmasına səbəb ola bilər, rsync-i dərhal 3.5.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ1
What versions of rsync are affected by CVE-2026-53794 and how is it resolved?
This vulnerability affects all versions of rsync prior to 3.5.0. Users are advised to immediately update to rsync version 3.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.