Skip to content
VulniPulse
Highest advisory severityCritical 2 vendors · 2 advisories

CVE-2026-70458

CVE-2026-70458: 2 tracked advisory records across Red Hat, Veeam. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-70458] Memory corruption via crafted file entries

    CVE-2026-70458Source published Source updated

    rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data. A flaw was found in rsync. This can lead to denial of service or other unpredictable system behavior. This Important out-of-bounds write vulnerability in rsync can lead to memory corruption when processing specially crafted file entries, potentially resulting in a denial of service. The flaw is triggered when hard-link preservation is inactive, allowing a remote attacker to…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    3 more entries in the full advisory.

    Source-reported affected versions
    • < 3.0.0
    • < 3.5.0
    Source-reported fixed versions
    • 3.5.0
    • rsync-0:3.5.0-3.el10_2
    • rsync-0:3.2.7-1.el9_8
    • RHSA-2026:67463

    1 more entries in the full advisory.

    Mitigation guidance
    • Disable the rsyncd daemon if unused (systemctl disable --now rsyncd), or strictly limit TCP/873 access to trusted clients via firewall rules. For daemons that must remain active, explicitly set refuse options = checksum in rsyncd.conf to block the demonstrated out-of-bounds write vector. Finally, when operating as a client pulling from untrusted peers, always append the --hard-links (-H) flag to force safe memory allocation and prevent corruption.

Veeam

1 advisory
  • Advisory severityCritical

    Critical [CVE-2020-14040 +67] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

    KB4825Source published

    This bulletin covers 68 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements. - Veeam Kasten for Kubernetes — Release Notes - Also resolves 8 Medium severity CVEs in the same and other packages. - Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. - Updated the Go runtime to resolve additional upstream Go CVEs. - Updated the bundled Prometheus Helm chart to resolve security issues. - Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory - Upgraded Dex image dependencies to resolve multiple Critical and…

    Related products — impact not confirmed
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • 8.5.10
    • 8.5.5
    • 1.26.1
    • 8.5.3

    20 more entries in the full advisory.

    Mitigation guidance
    • List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Veeam Kasten for Kubernetes | 7 | 7.5 | 8 | 8.5 | 9 Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: 2026-10-06 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Kasten for Kubernetes.
    • It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out.
    • Mitigation: Configure a bucket-level Default Object Lock retention so the object store stamps new objects at write time, or upgrade to Kasten 8.5.10.
    • Veeam Kasten for Kubernetes 8.5.5 Upgrade to Go 1.26.1 to address CVE-2026-25679 and CVE-2026-27142 Updated the UBI base image to address CVE-2026-4111 Veeam Kasten for Kubernetes 8.5.3 Upgrade to Go 1.25.7 to address CVE-2025-61732.

    4 more entries in the full advisory.

    Workarounds
    • Veeam Kasten for Kubernetes 8.0.14 Improved logging security for specific block mode datamover upload Pod invocations.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery