CLSA-2026-1777544655

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544655.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1777544655
Upstream
Published
2026-05-02T01:10:44Z
Modified
2026-06-01T00:33:18.629966160Z
Summary
rsync: Fix of 2 CVEs
Details
  • CVE-2024-12086: prevent server from reading arbitrary client files via path traversal
  • CVE-2025-10158: fix invalid access to files array in sender
  • Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator
  • Enable Amazon Linux 2 ELS
References

Affected packages

TuxCare:CentOS:7 / rsync

Package

Name
rsync
Purl
pkg:rpm/tuxcare/rsync?distro=centos-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.2-12.0.1.el7_9.tuxcare.els3

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544655.json"