Search CVE reports


Toggle filters

1 – 10 of 35 results


CVE-2026-27171

Low priority
Vulnerable

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

4 affected packages

zlib, rsync, klibc, zsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zlib Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rsync Not affected Not affected Vulnerable Vulnerable
klibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
zsync Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22184

Medium priority
Needs evaluation

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib...

4 affected packages

zlib, rsync, zsync, klibc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zlib Not affected Not affected Not affected Not affected
rsync Not affected Not affected Not affected Not affected
zsync Needs evaluation Needs evaluation Needs evaluation Needs evaluation
klibc Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-10158

Low priority
Needs evaluation

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-12747

Medium priority
Fixed

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-12088

Medium priority
Fixed

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-12087

Medium priority
Fixed

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-12086

Medium priority
Fixed

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-12085

Medium priority
Fixed

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-12084

High priority
Fixed

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes),...

1 affected package

rsync

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rsync Fixed Fixed Not affected Not affected
Show less packages

CVE-2023-45853

Medium priority
Fixed

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE:...

3 affected packages

zlib, rsync, klibc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zlib Not affected Not affected Not affected Not affected
rsync Not affected Not affected Not affected Not affected
klibc Not affected Not affected Not affected Not affected
Show less packages