CVE-2026-41035 Details
Description
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
A use-after-free vulnerability has been identified in rsync versions 3.0.1 through 3.4.1. The issue arises in the receive_xattr function, where an untrusted length value is used in a qsort call, leading to a use-after-free condition on the receiver side. This vulnerability is triggered when rsync is run with the -X (or --xattrs) option. On Linux, many common configurations are vulnerable, while non-Linux platforms are more widely affected.
Users can upgrade to rsync version 3.4.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | [email protected] |
| CWE-805 | Buffer Access with Incorrect Length Value | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| samba rsync | >= 3.0.1, <= 3.4.1 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | redhat-SADP |
| Aug 27, 2026 | CVE Modified | CVE |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 10, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 21, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CVE |
| Apr 16, 2026 | CVE Modified | CVE |
| Apr 16, 2026 | New CVE Received | [email protected] |