Release date:
2026-09-09 11:03:42 UTC
Description:
- CVE-2026-53784: refuse attacker-planted symlinks when a daemon module
resolves its absolute path with "use chroot = no"
- CVE-2026-53786: strip the module-dir prefix before checking a
client-supplied filter merge file against the module filter list
- CVE-2026-53789: keep implied parent directories non-content so a peer
cannot widen the scope of a --delete run
- CVE-2026-53803: open the batch, motd, lock, log and config files
refusing attacker-planted symlinks, and refuse a non-regular
--read-batch file
- CVE-2026-70459: reject a non-directory transfer-root file-list entry
- CVE-2026-70463: parse "auth users" with conf_strtok so an @Group Name
entry containing a space is not torn in two
Updated packages:
-
rsync-3.1.2-12.0.1.amzn2.tuxcare.els10.x86_64.rpm
sha:8a97ef029c18a737383ca38164424e86e2494e5e7cb3872d4ac696c34b2b68ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.