CVE-2025-10158 describes an out-of-bounds read vulnerability in rsync, where a malicious client can trigger a heap-based buffer overflow by providing a negative array index during a file transfer. This issue requires the malicious client to have at least read access to the remote rsync module. With a CVSS score of 4.3 (MEDIUM), the vulnerability has a low attack complexity and requires low privileges, but its impact is limited to a denial of service (availability) and does not affect confidentiality or integrity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 3.4.1CPE match | cpe:2.3:a:rsync:rsync:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
rsync vulnerabilities
Jun 1, 2026rsync vulnerabilities
May 20, 2026rsync: Rsync: Out of bounds array access via negative index
Nov 18, 2025Rsync: Out of bounds array access via negative index
Nov 11, 2025