Release date:
2026-09-24 16:23:45 UTC
Description:
- CVE-2026-53783: rrsync restricted-directory escape through a symlinked or
raced path component, --copy-unsafe-links, -D or a symlinked log file;
partial, the dir-merge rule escape needs --confine-root (3.5.0)
- CVE-2026-53790: the daemon's pre-xfer/post-xfer exec hooks and RSYNC_CONNECT_PROG
expanded %RSYNC_*%/%H into a shell command without escaping them
- CVE-2026-70453: unbounded hash_search() chain walk let a crafted run of equal weak
checksums pin the sender at 100% CPU; the per-offset walk is now bounded
- CVE-2026-70456: heap out-of-bounds write in read_args() when the peer's argument count
lands exactly on the argv allocation; room for the trailing NULL is reserved
- CVE-2026-70458: out-of-bounds write from a file entry marked FLAG_HLINKED accepted while
hard-link preservation was inactive; the flag is now gated and excludes dirs
- CVE-2026-70462: a peer-supplied MSG_IO_TIMEOUT could disable or overflow the client's own
I/O timeout; non-positive values are ignored and the value is capped
- CVE-2026-70464: the pre-transfer daemon handshake ran with no I/O timeout, so an
unauthenticated peer could hold every max-connections slot indefinitely
- safe_arg() left an uninitialized heap byte in remote-shell filename args
Updated packages:
-
rsync-3.1.3-19.el8.1.tuxcare.els11.i686.rpm
sha:5e7be5ca693f8986ad3b6ece837f3ec4675d53b9e012fa8ecd474e9f7ec149a5
-
rsync-3.1.3-19.el8.1.tuxcare.els11.x86_64.rpm
sha:179d3ed201f8b345bbb3efb8e84e909fd056ebca81898afb362a8691c6dbaca6
-
rsync-daemon-3.1.3-19.el8.1.tuxcare.els11.noarch.rpm
sha:f8b02d1382be05f8dfac5da5390f562dfaf1c8abd6d1ff32974d07824586177e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.