{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2026/cve-2026-53799-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-09T13:40:16Z",
      "generator": {
        "date": "2026-09-09T13:40:16Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-53799-ELS_OS-RHEL7ELS",
      "initial_release_date": "2026-08-13T15:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-13T15:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-01T13:25:30Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-09-01T17:13:58Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-09-09T13:40:16Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2026-53799"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rsync@3.1.2-12.0.1.el7_9?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.el7_9.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.el7_9.x86_64",
                  "product_id": "rsync-0:3.1.2-12.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rsync@3.1.2-12.el7_9?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els7?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                  "product_id": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.el7_9.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els6?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els10?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.el7_9.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53799",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53799"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-phxh-hjqv-39c9",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-phxh-hjqv-39c9"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-acl-xattr-application",
          "url": "https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-acl-xattr-application"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-01T14:12:34.949599Z",
          "details": "This flaw is local-only and high‑complexity: it requires an attacker to race a symlink substitution inside the destination path precisely between the data write and the subsequent ACL/xattr apply, and the vulnerable path is only exercised when rsync is run with --acls and/or --xattrs (or fake‑super)—flags that are not enabled by default (e.g., -a/--archive does not include them). Exploitation additionally depends on the attacker having write access within the destination directory to plant/replace the symlink, and the effect is limited to metadata (ACL/xattr) changes rather than arbitrary file content modification, yielding elevation only if rsync already has privilege to set those attributes. Given these narrow, non‑default preconditions and the need for local write access plus precise timing, the practical risk to centrally managed server/VM deployments is low and this CVE can be safely deprioritized.",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.x86_64"
          ]
        }
      ]
    }
  ]
}