CVE-2026-41035
Published: April 18, 2026Last modified: April 29, 2026
Description
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.8 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | rsync | Fixed (3.2.7-r3) |
| 25 LTS | rsync | Fixed (3.4.1-r2) | |
| Stream | rsync | Fixed (3.4.1-r2) |
References
- http://www.openwall.com/lists/oss-security/2026/04/16/9
- http://www.openwall.com/lists/oss-security/2026/04/22/3
- https://access.redhat.com/errata/RHSA-2026:17481
- https://access.redhat.com/errata/RHSA-2026:19152
- https://access.redhat.com/errata/RHSA-2026:19368
- https://access.redhat.com/errata/RHSA-2026:20601
- https://access.redhat.com/errata/RHSA-2026:20602
- https://access.redhat.com/errata/RHSA-2026:20603
- https://access.redhat.com/errata/RHSA-2026:20604
- https://access.redhat.com/errata/RHSA-2026:20696
- https://access.redhat.com/errata/RHSA-2026:23233
- https://access.redhat.com/errata/RHSA-2026:23245
- https://access.redhat.com/errata/RHSA-2026:25044
- https://access.redhat.com/errata/RHSA-2026:25149
- https://access.redhat.com/errata/RHSA-2026:25170
- https://access.redhat.com/errata/RHSA-2026:25172
- https://access.redhat.com/errata/RHSA-2026:25173
- https://access.redhat.com/errata/RHSA-2026:25181
- https://access.redhat.com/errata/RHSA-2026:25190
- https://access.redhat.com/errata/RHSA-2026:26542
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/security/cve/CVE-2026-41035
- https://bugzilla.redhat.com/show_bug.cgi?id=2458898
- https://github.com/RsyncProject/rsync/issues/871
- https://github.com/RsyncProject/rsync/releases
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41035.json
- https://www.openwall.com/lists/oss-security/2026/04/16/2