CVE-2026-53794
CVE-2026-53794: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium5.3
Medium [CVE-2026-53794] Denial of Service via --max-alloc=0 logic error
CVE-2026-53794Source published Source updated
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service. A flaw was found in rsync. This vulnerability in rsync is rated as Important. A remote attacker can exploit a logic error in the `--max-alloc` handling by providing `--max-alloc=0`, which disables memory allocation sanity checks. This can lead to unbounded memory consumption on the receiving system, resulting in a denial of service without requiring authentication or user…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4
- Red Hat package: rsync
- Source-reported affected versions
- < 3.5.0
- Source-reported fixed versions
- 3.5.0
- Mitigation guidance
- Avoid using the `--max-alloc=0` option in rsync configurations or command-line arguments. If rsync is operating as a daemon, ensure that its configuration does not include `--max-alloc=0`. For rsync clients, refrain from using `--max-alloc=0` when synchronizing with untrusted sources. This mitigation prevents the disabling of memory allocation sanity checks, thereby avoiding unbounded memory consumption. If rsync is running as a service, a restart may be required for configuration changes to take effect.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.