CVE-2026-70459

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 15:19

Updated : 2026-08-31 15:11


NVD link : CVE-2026-70459

Mitre link : CVE-2026-70459

CVE.ORG link : CVE-2026-70459


JSON object : View

Products Affected

samba

  • rsync
CWE
CWE-908

Use of Uninitialized Resource