Back

LOW

Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy

Published May 20, 2026

Description

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, ensure that the `RSYNC_PROXY` environment variable is not set. If rsync is configured to use an HTTP proxy via this variable, unsetting it will prevent exploitation. To unset the `RSYNC_PROXY` environment variable for the current session, use: `unset RSYNC_PROXY`. For a more permanent solution, ensure that `RSYNC_PROXY` is not defined in system-wide or user-specific environment configuration files. Note that this mitigation will disable rsync's ability to use an HTTP proxy, which may impact functionality if proxy usage is required.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 20, 2026
Updated Jul 14, 2026
Reserved May 11, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date May 20, 2026