[1/6] Cloning rsync repository... Cloning into '/tmp/rsync-variant-4301/rsync'... [2/6] Building rsync v3.4.2 (vulnerable)... [3/6] Building rsync v3.4.3 (fixed)... Vuln SHA: de3cc03b03be153092f266aa1117b4706947ed07 Fixed SHA: 2c7777aaa62abeb1bca192da345e6e8c685e872a [4/6] VARIANT 1: Overlong HTTP headers after valid status line Vuln exit: 1 | Fixed exit: 1 Vuln stack-overflow: false | Fixed stack-overflow: false | Fixed leak-only: true [5/6] VARIANT 2: Response ending with \r at buffer boundary Vuln exit: 1 | Fixed exit: 1 Vuln stack-overflow: true | Fixed stack-overflow: false | Fixed leak-only: true [6/6] VARIANT 3: Valid status line followed by overlong continuation Vuln exit: 1 | Fixed exit: 1 Vuln stack-overflow: false | Fixed stack-overflow: false | Fixed leak-only: true ========== VARIANT RESULTS ========== RESULT: A distinct variant trigger was found on the vulnerable version, but it does NOT bypass the fix on v3.4.3. See logs under /root/.pruva/runs/cve-2026-45232_20260522-095410/logs for details.