Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data. | |
| Title | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:36:31.894Z
Reserved: 2026-08-04T14:52:23.814Z
Link: CVE-2026-70458
Updated: 2026-08-13T15:36:24.358Z
Status : Received
Published: 2026-08-13T15:19:59.663
Modified: 2026-08-13T16:19:01.513
Link: CVE-2026-70458
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z