CVE-2025-10158

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.
Configurations

No configuration.

History

18 Nov 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 15:16

Updated : 2025-11-19 19:15


NVD link : CVE-2025-10158

Mitre link : CVE-2025-10158

CVE.ORG link : CVE-2025-10158


JSON object : View

Products Affected

No product.

CWE
CWE-129

Improper Validation of Array Index