CVE-2026-70462: Rsyncproject Rsync
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion.
Affected products
- Rsyncproject Rsync: from 3.1.0, up to and including 3.4.4
Published 2026-08-13. Last modified 2026-09-08.