{"id":"AZL-95840","summary":"CVE-2026-70462 affecting package rsync 3.4.3-1","details":"rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion.","modified":"2026-09-06T05:31:44Z","published":"2026-08-13T15:20:00Z","upstream":["CVE-2026-70462"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70462"}],"affected":[{"package":{"name":"rsync","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.4.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95840.json"}}],"schema_version":"1.9.0"}