Release date:
2026-09-28 09:01:39 UTC
Description:
* SECURITY UPDATE: --delete scope expansion by a malicious sender
- debian/patches/CVE-2026-53789.patch: downgrade implied-parent
directories to FLAG_IMPLIED_DIR on the receiver, covering synthetic and
legacy implied parents, so a sender cannot mark a parent as a content
dir and have delete_in_dir() sweep pre-existing siblings. The
parse_filter_file() module-dir strip that upstream bundled into the
same commit is not taken here: it is the CVE-2026-53786 fix per
upstream NEWS and ships in debian/patches/CVE-2026-53786.patch
- the patch's two regression tests are rewritten against this tree's shell
testsuite, as upstream's pytest-based ones need a harness 3.2.3 does not
have; debian/control gains python3 in Build-Depends for them
- CVE-2026-53789
Updated packages:
-
rsync_3.2.3-4+deb11u4+tuxcare.els5_amd64.deb
sha:6d8047cf302f1e6d5c50c41bc48fd1ed8a8d2e6c
-
rsync_3.2.3-4+deb11u4+tuxcare.els5_arm64.deb
sha:b35ba6476873ece5af0be1478a05c9ba5107958d
-
rsync_3.2.3-4+deb11u4+tuxcare.els5_armel.deb
sha:3e086bf1efbdd0ac616a256bb68d246086a0b354
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.