CVE-2026-41035: Samba Rsync

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

Affected products

  • Samba Rsync: from 3.0.1, up to and including 3.4.1

Published 2026-04-16. Last modified 2026-09-04.