Impact
The vulnerability is a resource‑exhaustion flaw in the rsync daemon that lets an unauthenticated remote attacker stall the handshake process to consume all available connection slots, preventing legitimate clients from connecting. This results in a denial of service, affecting only availability and potentially disrupting critical sync operations.
Affected Systems
The affected product is the rsync daemon from RsyncProject. Versions prior to 3.5.0, including the historically used 2.0.0, are vulnerable. All builds up to but not including 3.5.0 contain the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score is not available, making the current exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers can simply open many simultaneous TCP connections to the rsync port and stall the handshake or provide minimal data to avoid timeouts. No authentication is required, so any host exposing rsync on a remote port can be targeted.
OpenCVE Enrichment