Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:67463
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:67463
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:67463.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:67463
Upstream
CVE-2026-53783
CVE-2026-53784
CVE-2026-53785
CVE-2026-53789
CVE-2026-53790
CVE-2026-53791
CVE-2026-53793
CVE-2026-53795
CVE-2026-53802
CVE-2026-53803
CVE-2026-70452
CVE-2026-70453
CVE-2026-70454
CVE-2026-70455
CVE-2026-70456
CVE-2026-70457
CVE-2026-70458
CVE-2026-70460
CVE-2026-70461
CVE-2026-70463
CVE-2026-70464
Published
2026-09-15T10:17:15Z
Modified
2026-09-15T10:32:31Z
Severity
8.2 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: rsync security, bug fix, and enhancement update
Details
References
https://access.redhat.com/errata/RHSA-2026:67463
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2515368
https://bugzilla.redhat.com/show_bug.cgi?id=2515373
https://bugzilla.redhat.com/show_bug.cgi?id=2515378
https://bugzilla.redhat.com/show_bug.cgi?id=2515379
https://bugzilla.redhat.com/show_bug.cgi?id=2515380
https://bugzilla.redhat.com/show_bug.cgi?id=2515381
https://bugzilla.redhat.com/show_bug.cgi?id=2515384
https://bugzilla.redhat.com/show_bug.cgi?id=2515385
https://bugzilla.redhat.com/show_bug.cgi?id=2515386
https://bugzilla.redhat.com/show_bug.cgi?id=2515387
https://bugzilla.redhat.com/show_bug.cgi?id=2515389
https://bugzilla.redhat.com/show_bug.cgi?id=2515395
https://bugzilla.redhat.com/show_bug.cgi?id=2515396
https://bugzilla.redhat.com/show_bug.cgi?id=2515403
https://bugzilla.redhat.com/show_bug.cgi?id=2515406
https://bugzilla.redhat.com/show_bug.cgi?id=2515409
https://bugzilla.redhat.com/show_bug.cgi?id=2515417
https://bugzilla.redhat.com/show_bug.cgi?id=2515419
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67463.json
https://access.redhat.com/security/cve/CVE-2026-53783
https://www.cve.org/CVERecord?id=CVE-2026-53783
https://nvd.nist.gov/vuln/detail/CVE-2026-53783
https://github.com/RsyncProject/rsync/releases/tag/v3.5.0
https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5
https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync
https://access.redhat.com/security/cve/CVE-2026-53784
https://www.cve.org/CVERecord?id=CVE-2026-53784
https://nvd.nist.gov/vuln/detail/CVE-2026-53784
https://github.com/RsyncProject/rsync/security/advisories/GHSA-ffg2-fr5g-3rxw
https://www.vulncheck.com/advisories/rsync-path-traversal-via-symlink-module-root
https://access.redhat.com/security/cve/CVE-2026-53785
https://www.cve.org/CVERecord?id=CVE-2026-53785
https://nvd.nist.gov/vuln/detail/CVE-2026-53785
https://github.com/RsyncProject/rsync/security/advisories/GHSA-pph3-7xmf-rrqg
https://www.vulncheck.com/advisories/rsync-path-traversal-write-escape-via-relative-mode
https://access.redhat.com/security/cve/CVE-2026-53789
https://bugzilla.redhat.com/show_bug.cgi?id=2515375
https://www.cve.org/CVERecord?id=CVE-2026-53789
https://nvd.nist.gov/vuln/detail/CVE-2026-53789
https://github.com/RsyncProject/rsync/security/advisories/GHSA-fxwg-7hmf-xh5q
https://www.vulncheck.com/advisories/rsync-arbitrary-file-deletion-via-malicious-file-list
https://access.redhat.com/security/cve/CVE-2026-53790
https://www.cve.org/CVERecord?id=CVE-2026-53790
https://nvd.nist.gov/vuln/detail/CVE-2026-53790
https://github.com/RsyncProject/rsync/security/advisories/GHSA-5hcf-7xxm-rmqq
https://www.vulncheck.com/advisories/rsync-command-injection-via-multiple-code-paths
https://access.redhat.com/security/cve/CVE-2026-53791
https://www.cve.org/CVERecord?id=CVE-2026-53791
https://nvd.nist.gov/vuln/detail/CVE-2026-53791
https://github.com/RsyncProject/rsync/security/advisories/GHSA-h2q9-5fr8-w635
https://www.vulncheck.com/advisories/rsync-daemon-ip-spoofing-via-proxy-protocol-header
https://access.redhat.com/security/cve/CVE-2026-53793
https://www.cve.org/CVERecord?id=CVE-2026-53793
https://nvd.nist.gov/vuln/detail/CVE-2026-53793
https://github.com/RsyncProject/rsync/security/advisories/GHSA-wj7w-vh23-mm44
https://www.vulncheck.com/advisories/rsync-path-confinement-bypass-via-boundary-marker-in-chroot-mode
https://access.redhat.com/security/cve/CVE-2026-53795
https://www.cve.org/CVERecord?id=CVE-2026-53795
https://nvd.nist.gov/vuln/detail/CVE-2026-53795
https://github.com/RsyncProject/rsync/security/advisories/GHSA-m9vj-637x-v6pq
https://www.vulncheck.com/advisories/rsync-arbitrary-file-write-via-temp-dir-link-dest
https://access.redhat.com/security/cve/CVE-2026-53802
https://bugzilla.redhat.com/show_bug.cgi?id=2515416
https://www.cve.org/CVERecord?id=CVE-2026-53802
https://nvd.nist.gov/vuln/detail/CVE-2026-53802
https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4
https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following
https://access.redhat.com/security/cve/CVE-2026-53803
https://www.cve.org/CVERecord?id=CVE-2026-53803
https://nvd.nist.gov/vuln/detail/CVE-2026-53803
https://github.com/RsyncProject/rsync/security/advisories/GHSA-g9f4-7q66-9582
https://www.vulncheck.com/advisories/rsync-symlink-following-arbitrary-file-overwrite
https://access.redhat.com/security/cve/CVE-2026-70452
https://www.cve.org/CVERecord?id=CVE-2026-70452
https://nvd.nist.gov/vuln/detail/CVE-2026-70452
https://github.com/RsyncProject/rsync/security/advisories/GHSA-6692-28cx-wpqq
https://www.vulncheck.com/advisories/rsync-access-control-bypass-via-dns-resolution-failure
https://access.redhat.com/security/cve/CVE-2026-70453
https://www.cve.org/CVERecord?id=CVE-2026-70453
https://nvd.nist.gov/vuln/detail/CVE-2026-70453
https://github.com/RsyncProject/rsync/security/advisories/GHSA-8x5r-mjx8-83hv
https://www.vulncheck.com/advisories/rsync-algorithmic-complexity-dos-via-hash-search
https://access.redhat.com/security/cve/CVE-2026-70454
https://www.cve.org/CVERecord?id=CVE-2026-70454
https://nvd.nist.gov/vuln/detail/CVE-2026-70454
https://github.com/RsyncProject/rsync/security/advisories/GHSA-3c3x-ww2w-5r5p
https://www.vulncheck.com/advisories/rsync-tls-certificate-validation-bypass-via-ssl-openssl-mode
https://access.redhat.com/security/cve/CVE-2026-70455
https://www.cve.org/CVERecord?id=CVE-2026-70455
https://nvd.nist.gov/vuln/detail/CVE-2026-70455
https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjvj-qgqg-cvx9
https://www.vulncheck.com/advisories/rsync-dos-via-zt-zstandard-compression-thread-exhaustion
https://access.redhat.com/security/cve/CVE-2026-70456
https://www.cve.org/CVERecord?id=CVE-2026-70456
https://nvd.nist.gov/vuln/detail/CVE-2026-70456
https://github.com/RsyncProject/rsync/security/advisories/GHSA-78jc-79jv-v6rw
https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-read-args
https://access.redhat.com/security/cve/CVE-2026-70457
https://bugzilla.redhat.com/show_bug.cgi?id=2515407
https://www.cve.org/CVERecord?id=CVE-2026-70457
https://nvd.nist.gov/vuln/detail/CVE-2026-70457
https://github.com/RsyncProject/rsync/security/advisories/GHSA-pg7g-xqmr-xpfh
https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-parse-size-arg
https://access.redhat.com/security/cve/CVE-2026-70458
https://www.cve.org/CVERecord?id=CVE-2026-70458
https://nvd.nist.gov/vuln/detail/CVE-2026-70458
https://github.com/RsyncProject/rsync/security/advisories/GHSA-gg3m-4m9m-268h
https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-flag-hlinked-handling
https://access.redhat.com/security/cve/CVE-2026-70460
https://www.cve.org/CVERecord?id=CVE-2026-70460
https://nvd.nist.gov/vuln/detail/CVE-2026-70460
https://github.com/RsyncProject/rsync/security/advisories/GHSA-w3xf-j2r2-gv4x
https://www.vulncheck.com/advisories/rsync-path-traversal-via-partial-dir-backup-dir-symlink
https://access.redhat.com/security/cve/CVE-2026-70461
https://www.cve.org/CVERecord?id=CVE-2026-70461
https://nvd.nist.gov/vuln/detail/CVE-2026-70461
https://github.com/RsyncProject/rsync/security/advisories/GHSA-jhxm-j4mq-3fj4
https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-files-from-entry
https://access.redhat.com/security/cve/CVE-2026-70463
https://www.cve.org/CVERecord?id=CVE-2026-70463
https://nvd.nist.gov/vuln/detail/CVE-2026-70463
https://github.com/RsyncProject/rsync/security/advisories/GHSA-pfj8-79vq-xgvr
https://www.vulncheck.com/advisories/rsync-authorization-bypass-via-auth-users-directive-parsing
https://access.redhat.com/security/cve/CVE-2026-70464
https://www.cve.org/CVERecord?id=CVE-2026-70464
https://nvd.nist.gov/vuln/detail/CVE-2026-70464
https://github.com/RsyncProject/rsync/security/advisories/GHSA-hrwq-ccf7-rw5m
https://www.vulncheck.com/advisories/rsync-connection-slot-exhaustion-dos-via-handshake-stall
Affected packages
Red Hat:enterprise_linux:10.2
rsync-daemon
Package
Name
rsync-daemon
Purl
pkg:rpm/redhat/rsync-daemon
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"
rsync-rrsync
Package
Name
rsync-rrsync
Purl
pkg:rpm/redhat/rsync-rrsync
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"
rsync
Package
Name
rsync
Purl
pkg:rpm/redhat/rsync
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"
rsync-debuginfo
Package
Name
rsync-debuginfo
Purl
pkg:rpm/redhat/rsync-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"
rsync-debugsource
Package
Name
rsync-debugsource
Purl
pkg:rpm/redhat/rsync-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"
RHSA-2026:67463 - OSV