================================================================= ==7440==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7f747c600940 at pc 0x5637e8d5f86c bp 0x7fff26772ae0 sp 0x7fff26772ad0 WRITE of size 1 at 0x7f747c600940 thread T0 #0 0x5637e8d5f86b in establish_proxy_connection /tmp/rsync-cve-2026-45232-685/rsync/socket.c:95 #1 0x5637e8d5f86b in open_socket_out /tmp/rsync-cve-2026-45232-685/rsync/socket.c:294 #2 0x5637e8d6002b in open_socket_out_wrapped /tmp/rsync-cve-2026-45232-685/rsync/socket.c:384 #3 0x5637e8d7f78a in start_socket_client /tmp/rsync-cve-2026-45232-685/rsync/clientserver.c:137 #4 0x5637e8cd8142 in start_client /tmp/rsync-cve-2026-45232-685/rsync/main.c:1541 #5 0x5637e8cd8142 in main /tmp/rsync-cve-2026-45232-685/rsync/main.c:1850 #6 0x7f747e02a1c9 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 #7 0x7f747e02a28a in __libc_start_main_impl ../csu/libc-start.c:360 #8 0x5637e8cdac54 in _start (/tmp/rsync-cve-2026-45232-685/vuln/rsync+0x4ec54) (BuildId: 095c474e2c39a541894ab0a26d26ba52c1a6836e) Address 0x7f747c600940 is located in stack of thread T0 at offset 2368 in frame #0 0x5637e8d5e2ff in open_socket_out /tmp/rsync-cve-2026-45232-685/rsync/socket.c:186 This frame has 8 object(s): [48, 56) 'res0' (line 189) [80, 128) 'hints' (line 189) [160, 170) 'portbuf' (line 190) [192, 1216) 'buffer' (line 193) [1344, 2368) 'buffer' (line 55) <== Memory access at offset 2368 overflows this variable [2496, 3520) 'authbuf' (line 56) [3648, 5696) 'buf' (line 300) [5824, 7872) 'buf' (line 309) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *are* supported) SUMMARY: AddressSanitizer: stack-buffer-overflow /tmp/rsync-cve-2026-45232-685/rsync/socket.c:95 in establish_proxy_connection Shadow bytes around the buggy address: 0x7f747c600680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600880: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 =>0x7f747c600900: 00 00 00 00 00 00 00 00[f2]f2 f2 f2 f2 f2 f2 f2 0x7f747c600980: f2 f2 f2 f2 f2 f2 f2 f2 00 00 00 00 00 00 00 00 0x7f747c600a00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600a80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600b00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x7f747c600b80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==7440==ABORTING