CVE-2026-43618

Publication date 20 May 2026

Last updated 20 May 2026


Ubuntu priority

Description

The receiver's compressed-token decoder accumulated a 32-bit signed counter without overflow checking. A malicious sender can trigger an overflow that, with careful manipulation, leaks process memory contents to the attacker -- environment variables, passwords, heap and library pointers - -- significantly weakening ASLR and facilitating further exploitation.

Why is this CVE high priority?

rsync developers have rated this as being a high severity issue

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
rsync 26.04 LTS resolute
Fixed 3.4.1+ds1-7ubuntu0.2
25.10 questing
Fixed 3.4.1+ds1-5ubuntu1.2
24.04 LTS noble
Fixed 3.2.7-1ubuntu1.4
22.04 LTS jammy
Fixed 3.2.7-0ubuntu0.22.04.6
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities