[CLSA-2026:1790328600] Fix CVE(s): CVE-2026-53789, CVE-2026-70457
Type:
security
Severity:
Critical
Release date:
2026-09-28 09:01:39 UTC
Description:
* SECURITY UPDATE: --delete scope expansion by a malicious sender - debian/patches/CVE-2026-53789.patch: downgrade implied-parent directories to FLAG_IMPLIED_DIR on the receiver, covering synthetic and legacy implied parents, so a sender cannot mark a parent as a content dir and have delete_in_dir() sweep pre-existing siblings. The parse_filter_file() module-dir strip that upstream bundled into the same commit is not taken here: it is the CVE-2026-53786 fix per upstream NEWS and ships in debian/patches/CVE-2026-53786.patch - the patch's two regression tests are rewritten against this tree's shell testsuite, as upstream's pytest-based ones need a harness 3.2.3 does not have; debian/control gains python3 in Build-Depends for them - CVE-2026-53789
Updated packages:
  • rsync_3.2.3-4+deb11u4+tuxcare.els5_amd64.deb
    sha:6d8047cf302f1e6d5c50c41bc48fd1ed8a8d2e6c
  • rsync_3.2.3-4+deb11u4+tuxcare.els5_arm64.deb
    sha:b35ba6476873ece5af0be1478a05c9ba5107958d
  • rsync_3.2.3-4+deb11u4+tuxcare.els5_armel.deb
    sha:3e086bf1efbdd0ac616a256bb68d246086a0b354
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.