CVE Vulnerabilities

CVE-2026-45232

Off-by-one Error

Published: May 20, 2026 | Modified: May 21, 2026
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
RsyncSamba*3.4.3 (excluding)
RsyncUbuntudevel*
RsyncUbuntuesm-infra-legacy/trusty*
RsyncUbuntuesm-infra-legacy/xenial*
RsyncUbuntuesm-infra/bionic*
RsyncUbuntuesm-infra/focal*
RsyncUbuntuesm-infra/xenial*
RsyncUbuntujammy*
RsyncUbuntunoble*
RsyncUbuntuquesting*
RsyncUbunturesolute*
RsyncUbuntuupstream*

Potential Mitigations

References