Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-70453

CVE-2026-70453: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-70453] Denial of Service via Algorithmic Complexity

    CVE-2026-70453Source published Source updated

    rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service. A flaw was found in rsync. By sending a specially crafted file list, an attacker can exhaust the receiver's CPU resources, leading to service unavailability. This is particularly relevant in Red Hat environments where rsync is used for remote file synchronization and may be exposed to untrusted networks. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    3 more entries in the full advisory.

    Source-reported affected versions
    • < 3.5.0
    Source-reported fixed versions
    • 3.5.0
    • rsync-0:3.5.0-3.el10_2
    • rsync-0:3.2.7-1.el9_8
    • RHSA-2026:67463

    1 more entries in the full advisory.

    Mitigation guidance
    • Disable unused rsyncd services (systemctl disable --now rsyncd), or restrict daemon access to trusted clients via hosts allow and firewall rules. Avoid synchronizing with untrusted senders or pushing to untrusted receivers and upload modules to prevent processing malicious file lists. To contain potential Denial of Service, enforce CPU resource limits on rsync processes using systemd cgroups or ulimit -t to prevent a quadratic search walk from starving the host.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery