Vulnerability Description
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/rclone/rclone/security/advisories/GHSA-6jcg-q3wp-x2f4
- https://www.vulncheck.com/advisories/rclone-archive-backend-squashfs-parser-deni
- https://github.com/rclone/rclone/security/advisories/GHSA-6jcg-q3wp-x2f4
FAQ
What is CVE-2026-79775?
CVE-2026-79775 is a vulnerability with a CVSS score of 6.5 (MEDIUM). rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskf...
How severe is CVE-2026-79775?
CVE-2026-79775 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79775?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.