[CLSA-2026:1789029225] rsync: Fix of 5 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-10 08:34:00 UTC
Description:
- CVE-2026-53784: confine the daemon's absolute chdir target with a new ownership-walk resolver so a planted parent symlink cannot steer a "use chroot = no" module root outside the module - CVE-2026-53786: strip a real module_dir prefix before the daemon-filter check on a merge-file path -- leaving the daemon's own "include from" / "exclude from" paths alone -- and treat a hidden merge file as non-existent - CVE-2026-53803: open the batch stream and replay script, motd, lock, log and config files through the ownership-walk resolver, and refuse a non-regular --read-batch file - CVE-2026-53789: clean a requested path's trailing slash and keep an implied-parent directory non-content, blocking --delete widening - CVE-2026-70459: reject a non-directory transfer-root entry
Updated packages:
  • rsync-3.0.6-12.el6.tuxcare.els10.x86_64.rpm
    sha:4b11bd3faddef83ba50288b8db30427961d60941d5d8b4469e406be01e44f36b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.