Release date:
2026-09-07 09:31:23 UTC
Description:
- CVE-2026-70463: parse "auth users" with conf_strtok so a leading comma splits
on commas alone, restoring "@Group Name" deny/:ro rules that whitespace
tokenisation had silently discarded (authorization bypass)
- CVE-2026-53786: strip the module_dir prefix before checking a client-supplied
--filter merge file against daemon_filter_list, so module filter rules can no
longer be bypassed
- CVE-2026-70459: reject a non-directory "." / "/." transfer-root file-list
entry and require dir_flist to hold an entry before trusting parent_ndx 0,
fixing the wild-pointer read that crashed the daemon child
- CVE-2026-53789: force implied-parent directories non-content on the receiver,
including the synthetic transfer root and the legacy protocol < 30
XMIT_TOP_DIR path, so a malicious sender cannot widen --delete scope
Updated packages:
-
rsync-3.1.3-19.el8.1.tuxcare.els9.x86_64.rpm
sha:5b8fad7806bc2fe10df87519685b6f18c142b023be6f640c6ef248d226173897
-
rsync-daemon-3.1.3-19.el8.1.tuxcare.els9.noarch.rpm
sha:e499fd449dc319ed343f04ace2507638ddd6c0f8ed8f09d5d0eb7ec3ee5cfc44
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.