Rsync: heap buffer overflow in rsync due to improper checksum length handling
Keep watching. It has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Rsync has a critical flaw where an attacker can crash the service or potentially run malicious code by sending specially crafted data that overflows a buffer used for checksums. This happens because the program doesn't properly limit how much data it writes to memory.
A heap buffer overflow in rsync's checksum handling allows an attacker to write beyond the bounds of the sum2 buffer when MAX_DIGEST_LEN exceeds SUM_LENGTH (16 bytes). The vulnerability stems from improper validation of attacker-controlled s2length parameters, enabling remote code execution or denial of service against rsync daemon instances.