Rsync: Out of bounds array access via negative index
Vulnerability Description
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10158
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Calum Hutton
References
More from rsync
View All →Affected Vendor
rsync
View all reports →