Release date:
2026-09-09 11:29:28 UTC
Description:
- CVE-2026-53784: refuse attacker-planted symlinks when a daemon module
resolves its absolute path with "use chroot = no"
- CVE-2026-53786: strip the module-dir prefix before checking a
client-supplied filter merge file against the module filter list
- CVE-2026-53789: keep implied parent directories non-content so a peer
cannot widen the scope of a --delete run
- CVE-2026-53803: open the batch, motd, lock, log and config files
refusing attacker-planted symlinks, and refuse a non-regular
--read-batch file
- CVE-2026-70459: reject a non-directory transfer-root file-list entry
- CVE-2026-70463: parse "auth users" with conf_strtok so an @Group Name
entry containing a space is not torn in two
Updated packages:
-
rsync-3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64.rpm
sha:cd1dfa90e6ffccb49261f4f4163e0c0128249b5ff1b567972857c8d1d6294dab
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.