Release date:
2026-09-10 08:34:00 UTC
Description:
- CVE-2026-53784: confine the daemon's absolute chdir target with a new
ownership-walk resolver so a planted parent symlink cannot steer a
"use chroot = no" module root outside the module
- CVE-2026-53786: strip a real module_dir prefix before the daemon-filter
check on a merge-file path -- leaving the daemon's own "include from" /
"exclude from" paths alone -- and treat a hidden merge file as
non-existent
- CVE-2026-53803: open the batch stream and replay script, motd, lock,
log and config files through the ownership-walk resolver, and refuse a
non-regular --read-batch file
- CVE-2026-53789: clean a requested path's trailing slash and keep an
implied-parent directory non-content, blocking --delete widening
- CVE-2026-70459: reject a non-directory transfer-root entry
Updated packages:
-
rsync-3.0.6-12.el6.tuxcare.els10.x86_64.rpm
sha:4b11bd3faddef83ba50288b8db30427961d60941d5d8b4469e406be01e44f36b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.