Back

MEDIUM

rclone local: crafted Range request against a translated symlink panics (DoS)

Published Sep 10, 2026

Description

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 10, 2026
Updated Sep 10, 2026
Reserved Sep 9, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity Moderate
Public date Sep 10, 2026
GHSA-P6M2-R3W9-MPXW