CVE-2025-10158
MEDIUMRsync - Out-of-Bounds Read via Negative Array Index
Title source: llmDescription
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Scores
CVSS v3
4.3
EPSS
0.0005
EPSS Percentile
14.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-129
Status
published
Products (1)
rsync/rsync
< 3.4.1
Published
Nov 18, 2025
Tracked Since
Feb 18, 2026