Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-53794

CVE-2026-53794: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.3

    Medium [CVE-2026-53794] Denial of Service via --max-alloc=0 logic error

    CVE-2026-53794Source published Source updated

    rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service. A flaw was found in rsync. This vulnerability in rsync is rated as Important. A remote attacker can exploit a logic error in the `--max-alloc` handling by providing `--max-alloc=0`, which disables memory allocation sanity checks. This can lead to unbounded memory consumption on the receiving system, resulting in a denial of service without requiring authentication or user…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat OpenShift Container Platform 4
    • Red Hat package: rsync
    Source-reported affected versions
    • < 3.5.0
    Source-reported fixed versions
    • 3.5.0
    Mitigation guidance
    • Avoid using the `--max-alloc=0` option in rsync configurations or command-line arguments. If rsync is operating as a daemon, ensure that its configuration does not include `--max-alloc=0`. For rsync clients, refrain from using `--max-alloc=0` when synchronizing with untrusted sources. This mitigation prevents the disabling of memory allocation sanity checks, thereby avoiding unbounded memory consumption. If rsync is running as a service, a restart may be required for configuration changes to take effect.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery