rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | rsync-0:3.5.0-3.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |