Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service. | |
| Title | rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error | |
| Weaknesses | CWE-1284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:34:33.994Z
Reserved: 2026-06-10T20:14:32.827Z
Link: CVE-2026-53794
Updated: 2026-08-13T15:34:29.044Z
Status : Received
Published: 2026-08-13T15:19:43.853
Modified: 2026-08-13T16:18:06.893
Link: CVE-2026-53794
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z