[CLSA-2026:1788773469] rsync: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-07 09:31:23 UTC
Description:
- CVE-2026-70463: parse "auth users" with conf_strtok so a leading comma splits on commas alone, restoring "@Group Name" deny/:ro rules that whitespace tokenisation had silently discarded (authorization bypass) - CVE-2026-53786: strip the module_dir prefix before checking a client-supplied --filter merge file against daemon_filter_list, so module filter rules can no longer be bypassed - CVE-2026-70459: reject a non-directory "." / "/." transfer-root file-list entry and require dir_flist to hold an entry before trusting parent_ndx 0, fixing the wild-pointer read that crashed the daemon child - CVE-2026-53789: force implied-parent directories non-content on the receiver, including the synthetic transfer root and the legacy protocol < 30 XMIT_TOP_DIR path, so a malicious sender cannot widen --delete scope
Updated packages:
  • rsync-3.1.3-19.el8.1.tuxcare.els9.x86_64.rpm
    sha:5b8fad7806bc2fe10df87519685b6f18c142b023be6f640c6ef248d226173897
  • rsync-daemon-3.1.3-19.el8.1.tuxcare.els9.noarch.rpm
    sha:e499fd449dc319ed343f04ace2507638ddd6c0f8ed8f09d5d0eb7ec3ee5cfc44
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.