Known Vulnerabilities for Rsync by Samba

Listed below are 10 of the newest known vulnerabilities associated with "Rsync" by "Samba".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-41035 json In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver us... Not Provided 2026-04-16 2026-04-16
CVE-2024-12747 json A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's... Not Provided 2025-01-14 2026-04-14
CVE-2024-12088 json A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link... Not Provided 2025-01-14 2026-04-14
CVE-2024-12087 json A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-ena... Not Provided 2025-01-14 2026-04-14
CVE-2024-12086 json A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. ... Not Provided 2025-01-14 2026-04-14
CVE-2024-12085 json A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipu... Not Provided 2025-01-14 2026-04-14
CVE-2022-29154 json An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the direct... 7.4 - HIGH 2022-08-02 2023-11-07
CVE-2020-14387 json A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerabilit... 7.4 - HIGH 2021-05-27 2021-06-09
CVE-2018-5764 json The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, whic... 7.5 - HIGH 2018-01-17 2023-11-07
CVE-2017-17434 json The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filte... 9.8 - CRITICAL 2017-12-06 2023-11-07

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationSambaRsync3.1.3
ApplicationSambaRsync3.1.3
ApplicationSambaRsync3.1.3
ApplicationSambaRsync3.1.2
ApplicationSambaRsync3.1.2
ApplicationSambaRsync3.1.2
ApplicationSambaRsync3.1.1
ApplicationSambaRsync3.1.1
ApplicationSambaRsync3.1.1
ApplicationSambaRsync3.1.1
ApplicationSambaRsync3.1.0
ApplicationSambaRsync3.1.0
ApplicationSambaRsync3.1.0
ApplicationSambaRsync3.0.9
ApplicationSambaRsync3.0.9
ApplicationSambaRsync3.0.9
ApplicationSambaRsync3.0.9
ApplicationSambaRsync3.0.8
ApplicationSambaRsync3.0.8
ApplicationSambaRsync3.0.8
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report