Nick Craig-Wood 50b4d4c745 serve sftp: don't crash the whole server on a bad request GHSA-6jcg-q3wp-x2f4
Three ways a single client could deny service to everyone else connected to
the same serve sftp process:

A session "subsystem" request payload is a length-prefixed string, but it was
sliced at a fixed offset without checking its length, so a client sending a
truncated payload panicked the out-of-band request goroutine and killed the
process. Decode the payload instead, the way the neighbouring "exec" request
already does.

Rejecting a request then left the goroutine handling that channel waiting
forever to learn what kind of channel it was, because nothing was ever sent
on the channel it waits on. A client could open channels in a loop making
unsupported requests and grow the server's goroutines and memory without
bound. Signal the waiter when the requests run out so the channel is torn
down.

Separately, the request handlers - and reads, writes and closes on the file
handles they return - run on pkg/sftp packet worker goroutines which have no
panic recovery. A panic raised by a backend while serving one request took the
process down with it. Recover panics at that boundary, log them with a stack
trace, and return them to the requesting client as an error instead.

Addresses GHSA-6jcg-q3wp-x2f4.
2026-07-31 13:21:59 +01:00
2026-04-11 15:27:05 +01:00
2026-05-15 20:12:47 +02:00
2025-08-22 11:42:51 +01:00
2026-05-01 15:56:56 +01:00
2026-05-01 15:56:56 +01:00
2026-05-01 15:56:56 +01:00
2020-10-28 18:16:23 +00:00
2026-05-01 15:56:56 +01:00
2019-09-29 11:05:10 +01:00
2026-05-01 17:15:20 +01:00

rclone logo

rclone logo

Website | Documentation | Download | Contributing | Changelog | Installation | Forum

Build Status Go Report Card GoDoc Docker Pulls

Rclone

Rclone ("rsync for cloud storage") is a command-line program to sync files and directories to and from different cloud storage providers.

Storage providers

  • 1Fichier 📄
  • Akamai Netstorage 📄
  • Alibaba Cloud (Aliyun) Object Storage System (OSS) 📄
  • Amazon S3 📄
  • ArvanCloud Object Storage (AOS) 📄
  • Bizfly Cloud Simple Storage 📄
  • Backblaze B2 📄
  • Box 📄
  • Ceph 📄
  • China Mobile Ecloud Elastic Object Storage (EOS) 📄
  • Citrix ShareFile 📄
  • Cloudflare R2 📄
  • Cloudinary 📄
  • Cubbit DS3 📄
  • DigitalOcean Spaces 📄
  • Digi Storage 📄
  • Dreamhost 📄
  • Drime 📄
  • Dropbox 📄
  • Enterprise File Fabric 📄
  • Exaba 📄
  • Fastly Object Storage 📄
  • Fastmail Files 📄
  • FileLu 📄
  • Filen 📄
  • Files.com 📄
  • FlashBlade 📄
  • FTP 📄
  • GoFile 📄
  • Google Cloud Storage 📄
  • Google Drive 📄
  • Google Photos 📄
  • HDFS (Hadoop Distributed Filesystem) 📄
  • Hetzner Object Storage 📄
  • Hetzner Storage Box 📄
  • HiDrive 📄
  • Hitachi Content Platform (HCP) 📄
  • HTTP 📄
  • Huawei Cloud Object Storage Service(OBS) 📄
  • Huawei Drive 📄
  • iCloud Drive 📄
  • ImageKit 📄
  • Internet Archive 📄
  • Internxt 📄
  • Jottacloud 📄
  • IBM COS S3 📄
  • Impossible Cloud 📄
  • Intercolo Object Storage 📄
  • IONOS Cloud 📄
  • Koofr 📄
  • Leviia Object Storage 📄
  • Liara Object Storage 📄
  • Linkbox 📄
  • Linode Object Storage 📄
  • Magalu Object Storage 📄
  • Mail.ru Cloud 📄
  • Memset Memstore 📄
  • MEGA 📄
  • MEGA S4 Object Storage 📄
  • Memory 📄
  • Microsoft Azure Blob Storage 📄
  • Microsoft Azure Files Storage 📄
  • Microsoft OneDrive 📄
  • Minio 📄
  • Nextcloud 📄
  • Blomp Cloud Storage 📄
  • OpenDrive 📄
  • OpenStack Swift 📄
  • Oracle Cloud Storage 📄
  • Oracle Object Storage 📄
  • Outscale 📄
  • OVHcloud Object Storage (Swift) 📄
  • OVHcloud Object Storage (S3-compatible) 📄
  • ownCloud 📄
  • pCloud 📄
  • Petabox 📄
  • PikPak 📄
  • Pixeldrain 📄
  • premiumize.me 📄
  • put.io 📄
  • Proton Drive 📄
  • QingStor 📄
  • Qiniu Cloud Object Storage (Kodo) 📄
  • Rabata Cloud Storage 📄
  • Quatrix 📄
  • Rackspace Cloud Files 📄
  • RackCorp Object Storage 📄
  • rsync.net 📄
  • Scaleway 📄
  • Scality (RING / ARTESCA) 📄
  • Seafile 📄
  • Seagate Lyve Cloud 📄
  • SeaweedFS 📄
  • Selectel Object Storage 📄
  • Servercore Object Storage 📄
  • SFTP 📄
  • Shade 📄
  • SMB / CIFS 📄
  • Spectra Logic 📄
  • Storj 📄
  • SugarSync 📄
  • Synology C2 Object Storage 📄
  • Tencent Cloud Object Storage (COS) 📄
  • Uloz.to 📄
  • US3 Object Storage 📄
  • Wasabi 📄
  • WebDAV 📄
  • Yandex Disk 📄
  • Zadara Object Storage 📄
  • Zero Services (ZERO-Z3) 📄
  • Zoho WorkDrive 📄
  • Zata.ai 📄
  • The local filesystem 📄

Please see the full list of all storage providers and their features

Virtual storage providers

These backends adapt or modify other storage providers

  • Alias: rename existing remotes 📄
  • Archive: read archive files 📄
  • Cache: cache remotes (DEPRECATED) 📄
  • Chunker: split large files 📄
  • Combine: combine multiple remotes into a directory tree 📄
  • Compress: compress files 📄
  • Crypt: encrypt files 📄
  • Hasher: hash files 📄
  • Union: join multiple remotes to work together 📄

Features

  • MD5/SHA-1 hashes checked at all times for file integrity
  • Timestamps preserved on files
  • Partial syncs supported on a whole file basis
  • Copy mode to just copy new/changed files
  • Sync (one way) mode to make a directory identical
  • Bisync (two way) to keep two directories in sync bidirectionally
  • Check mode to check for file hash equality
  • Can sync to and from network, e.g. two different cloud accounts
  • Optional large file chunking (Chunker)
  • Optional transparent compression (Compress)
  • Optional encryption (Crypt)
  • Optional FUSE mount (rclone mount)
  • Multi-threaded downloads to local disk
  • Can serve local or remote files over HTTP/WebDAV/FTP/SFTP/DLNA

Installation & documentation

Please see the rclone website for:

Downloads

License

This is free software under the terms of the MIT license (check the COPYING file included in this package).

S
Description
Forked rclone with Dropbox ListR, --delta-list bisync, fail-closed listings
Readme
200 MiB
Languages
Go 98.5%
Shell 0.4%
Python 0.4%
HTML 0.3%
JavaScript 0.2%
Other 0.1%