Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
Published May 20, 2026
2.1
LOWCVSS 4.0
EPSS 0.35%
Description
Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.
Affected products
-
- Version 0StatusaffectedConstraints<3.4.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| RsyncProject | Rsync | unaffected |
|
No data.
Red Hat Enterprise Linux 10
rsync
Fix deferred
Red Hat Enterprise Linux 6
rsync
Fix deferred
Red Hat Enterprise Linux 7
rsync
Fix deferred
Red Hat Enterprise Linux 8
rsync
Fix deferred
Red Hat Enterprise Linux 9
rsync
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | rsync | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | rsync | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | rsync | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | rsync | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, ensure that the `RSYNC_PROXY` environment variable is not set. If rsync is configured to use an HTTP proxy via this variable, unsetting it will prevent exploitation. To unset the `RSYNC_PROXY` environment variable for the current session, use: `unset RSYNC_PROXY`. For a more permanent solution, ensure that `RSYNC_PROXY` is not defined in system-wide or user-specific environment configuration files. Note that this mitigation will disable rsync's ability to use an HTTP proxy, which may impact functionality if proxy usage is required.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
2 other sources (Red Hat, CVE.org) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.35% (0.00347) | 25.96th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.35% (0.00350) | 26.67th | v5 (v2026.06.15) |
| May 20, 2026 | 0.03% (0.00031) | 9.11th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-45232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480057 Issue Tracking
- https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 release-notesRelease Notes
- https://github.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45232
- https://www.cve.org/CVERecord?id=CVE-2026-45232
- https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-45232 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2480057 | Issue Tracking | |
| https://github.com/RsyncProject/rsync/releases/tag/v3.4.3 | release-notesRelease Notes | |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45232 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-45232 | ||
| https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.