CVE 4.3 MEDIUM

Rsync: Out of bounds array access via negative index_CVE-2025-10158

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The

malicious

rsync client requires at least read access to the remote rsync module in order to trigger the issue.

Basic Information

ID CVE-2025-10158
Source rapid7
Published Nov 18, 2025 at 14:24
Modified Nov 18, 2025 at 14:45

Affected Product

Vendor rsync
Product rsync
Affected Versions rsync rsync 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.