[1/6] Cloning rsync repository... Cloning into '/tmp/rsync-variant-15708/rsync'... [2/6] Building rsync v3.4.2 (vulnerable)... [3/6] Building rsync v3.4.3 (fixed)... Vuln SHA: de3cc03b03be153092f266aa1117b4706947ed07 Fixed SHA: 2c7777aaa62abeb1bca192da345e6e8c685e872a [4/6] VARIANT 1: Overlong HTTP headers after valid status line Vuln exit: 1 | Fixed exit: 1 [5/6] VARIANT 2: Response ending with \r at buffer boundary Vuln exit: 1 | Fixed exit: 1 [6/6] VARIANT 3: Long proxy credentials near buffer limit Vuln exit: 1 | Fixed exit: 1 ========== VARIANT RESULTS ========== VARIANT 1: Overlong HTTP headers after valid status line Vulnerable ASan crash: true (exit 1) Fixed ASan crash: true (exit 1) VARIANT 2: Response with \r at buffer boundary Vulnerable ASan crash: true (exit 1) Fixed ASan crash: true (exit 1) VARIANT 3: Long proxy credentials Vulnerable ASan crash: true (exit 1) Fixed ASan crash: true (exit 1) RESULT: A bypass variant was found that reproduces on the fixed version. See logs under /root/.pruva/runs/cve-2026-45232_20260522-095410/logs for details.