Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-70456

CVE-2026-70456: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-70456] Heap Out-of-Bounds Write via crafted argument list

    CVE-2026-70456Source published Source updated

    rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. A flaw was found in rsync. This could lead to corruption of adjacent memory, potentially causing a denial of service or, in some cases, arbitrary code execution. This is an Important severity flaw in rsync, allowing a remote attacker to corrupt heap memory via a specially crafted argument list. The vulnerability, exploitable without authentication or user interaction, could lead to denial of service or…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    3 more entries in the full advisory.

    Source-reported affected versions
    • < 3.0.1
    • < 3.5.0
    Source-reported fixed versions
    • 3.5.0
    • rsync-0:3.5.0-3.el10_2
    • rsync-0:3.2.7-1.el9_8
    • RHSA-2026:67463

    1 more entries in the full advisory.

    Mitigation guidance
    • To mitigate this issue, restrict network access to rsync services to trusted hosts and networks using firewall rules. If rsync is used in daemon mode, configure `rsyncd.conf` to limit access. When using rsync as a client, avoid synchronizing with untrusted rsync servers.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery