PatchSiren cyber security CVE debrief
CVE-2026-70457 RsyncProject CVE debrief
The CVE-2026-70457 vulnerability is an out-of-bounds write issue in the parse_size_arg() function of rsync versions 3.2.3 before 3.5.0. This occurs when the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. If snprintf truncates the formatted size string, the return value may exceed the array length, leading to memory corruption outside the intended array bounds. The vulnerability has a HIGH CVSS score of 8.3, indicating a high level of severity. System administrators and security teams responsible for rsync installations, particularly in environments where rsync is used for data synchronization across networks, should prioritize patching or mitigating this vulnerability. Users of rsync versions before 3.5.0 should take immediate action to assess and mitigate potential risks associated with this vulnerability. Evidence is based on official CVE and NVD records, as well as vendor advisories. Limited details are available on exploitability and affected systems.
- Vendor
- RsyncProject
- Product
- rsync
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-26
Who should care
System administrators and security teams responsible for rsync installations, particularly in environments where rsync is used for data synchronization across networks. Users of rsync versions before 3.5.0 should prioritize patching or mitigating this vulnerability due to its HIGH CVSS score of 8.3.
Technical summary
The CVE-2026-70457 vulnerability is an out-of-bounds write issue in the parse_size_arg() function of rsync versions 3.2.3 before 3.5.0. This occurs when the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. If snprintf truncates the formatted size string, the return value may exceed the array length, leading to memory corruption outside the intended array bounds.
Defensive priority
High-priority defensive actions are recommended due to the HIGH CVSS score of 8.3. Immediate attention is required to assess and mitigate potential risks associated with rsync versions before 3.5.0.
Recommended defensive actions
- Inventory rsync installations and verify versions are 3.5.0 or later
- Apply vendor patches or upgrades for rsync
- Monitor rsync logs for potential exploitation attempts
- Implement compensating controls such as restricting rsync access
- Exception tracking for rsync usage
Evidence notes
Evidence is based on official CVE and NVD records, as well as vendor advisories. The CVE description indicates an out-of-bounds write vulnerability in rsync 3.2.3 before 3.5.0 in the parse_size_arg() function. Limited details are available on exploitability and affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70457 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70457
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70457 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70457
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/RsyncProject/rsync/releases/tag/v3.5.0
-
Source reference
Unverified legacy reference
URL: https://github.com/RsyncProject/rsync/security/advisories/GHSA-pg7g-xqmr-xpfh
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-parse-size-arg
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.