CVE-2026-41035
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. T
CVSS
7.4
Alto
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Publicado: 16 abr 2026 · Última mod.: 4 sept 2026 · CWE-130 · CWE-805
0.4%EPSS · 30 días0.4%
2026-08-242026-09-22
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
- github.comhttps://github.com/RsyncProject/rsync/issues/871
- github.comhttps://github.com/RsyncProject/rsync/releases
- www.openwall.comhttps://www.openwall.com/lists/oss-security/2026/04/16/2
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/16/9
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/22/3
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:17481
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19152
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19368
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20601
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20602
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20603
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20604
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20696
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23233
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23245
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25044
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25149
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25170
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25172
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25173
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-77619——
——0Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a minimal frame declaring a multi-gigabyte payload, causing an excessive allocation that can abort Vector or invoke the host OOM killer. Because the allocation follows the declared length rather than bytes transmitted, the attacker has low resource cost, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0.4hCVE-2023-57787.5 ALT21.7%
——7Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900.
This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC700: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC800: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance Controller AC900: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1.4dCVE-2026-202905.8 MED8.9%
——3A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.
This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.4dCVE-2026-734557.5 ALT40.3%
——12On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.6dCVE-2026-906787.5 ALT43.2%
——13An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length header, the HTTP/3 multiplexer credits the length declared in a DATA frame header to the stream endpoint's known-input-payload estimate at the moment the frame header is decoded, before the payload has been received, and that declared length is emitted verbatim as the HTTP/1.1 chunk size. A remote unauthenticated client that declares more payload than it delivers and then ends the stream causes HAProxy to announce a chunk larger than the bytes it writes and to return the connection to the idle pool in a desynchronized state. The result is potential HTTP request smuggling on reused backend connections: an attacker can place a request past a frontend rule such as a path-based http-request deny, so that the smuggled request is never seen by HAProxy's HTTP analysis, and can cause concurrent clients' requests, including their request lines and Authorization headers, to be consumed as the attacker's request body and lost. Exploitation is not deterministic; it depends on a race with backend connection pooling, succeeding in a majority of but not all trials during testing, and can be retried freely. The mechanism was introduced in 3.3-dev10; releases 3.2.x and earlier are unaffected.55mCVE-2026-15418—5.0%
——1In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.12d