rclone local: crafted Range request against a translated symlink panics (DoS)
Published Sep 10, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.36%
Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1.
Affected products
-
- Version < 1.75.1StatusaffectedConstraints-
- Version
No data.
OpenShift Service Mesh 3
openshift-golang-builder-container
Affected
Red Hat OpenShift Container Platform 4
openshift-golang-builder-container
Not affected
Red Hat OpenShift Container Platform 4
openshift-golang-builder-container/openshift-golang-builder-container
Not affected
Red Hat OpenShift Virtualization 4
openshift-golang-builder-container
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 3 | openshift-golang-builder-container | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-golang-builder-container | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-golang-builder-container/openshift-golang-builder-container | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-golang-builder-container | Not affected | n/a |
github.com/rclone/rclone
Go
Introduced 0 Fixed 1.75.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rclone/rclone | 0 | 1.75.1 |
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-88015 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2531541 Issue Tracking
- https://github.com/advisories/GHSA-p6m2-r3w9-mpxw Advisory
- https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 x_refsource_MISC
- https://github.com/rclone/rclone/releases/tag/v1.75.1 x_refsource_MISC
- https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-88015
- https://www.cve.org/CVERecord?id=CVE-2026-88015
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-88015 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2531541 | Issue Tracking | |
| https://github.com/advisories/GHSA-p6m2-r3w9-mpxw | Advisory | |
| https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 | x_refsource_MISC | |
| https://github.com/rclone/rclone/releases/tag/v1.75.1 | x_refsource_MISC | |
| https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-88015 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-88015 |
Change history (0)
No recorded changes yet.