VDB

CVE-2026-41035

CVE-2026-41035 PUBLISHED CVSS 7.400000095367432 HIGH

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

EPSS 0.03% · 8.1th percentile

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS Score
0.03%
8.1th percentile

Affected Products

VendorProductVersions
Sambarsync3.0.1
sambarsync3.0.1

Timeline

  • Apr 16, 2026 EPSS Score
  • Apr 16, 2026 CVE Published
  • Apr 17, 2026 Security Advisory
  • Apr 22, 2026 CVE Updated
  • May 14, 2026 Distribution Patch
  • May 14, 2026 Security Advisory
  • May 16, 2026 Distribution Patch
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 19, 2026 Distribution Patch
  • May 19, 2026 Security Advisory
  • May 20, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›