rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory. | |
| Title | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() | |
| Weaknesses | CWE-131 CWE-787 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T17:33:51.308Z
Reserved: 2026-08-04T14:52:23.814Z
Link: CVE-2026-70457
No data.
Status : Received
Published: 2026-08-13T15:19:59.490
Modified: 2026-08-13T18:18:15.867
Link: CVE-2026-70457
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z