[CLSA-2026:1788952286] rsync: Fix of 6 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-09 11:11:40 UTC
Description:
- CVE-2026-53784: refuse attacker-planted symlinks when a daemon module resolves its absolute path with "use chroot = no" - CVE-2026-53786: strip the module-dir prefix before checking a client-supplied filter merge file against the module filter list - CVE-2026-53789: keep implied parent directories non-content so a peer cannot widen the scope of a --delete run - CVE-2026-53803: open the batch, motd, lock, log and config files refusing attacker-planted symlinks, and refuse a non-regular --read-batch file - CVE-2026-70459: reject a non-directory transfer-root file-list entry - CVE-2026-70463: parse "auth users" with conf_strtok so an @Group Name entry containing a space is not torn in two
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64.rpm
    sha:71de68b58930eb0e338434a8a84760069df5bfe23494f525905bc63a66a08ef1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.