RLSA-2026:67463

Source
https://errata.rockylinux.org/RLSA-2026:67463
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:67463.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:67463
Upstream
Published
2026-09-15T12:08:56Z
Modified
2026-09-15T12:30:03Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Important: rsync security, bug fix, and enhancement update
Details

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

  • rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)

  • rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454)

  • rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)

  • rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)

  • rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)

  • rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)

  • rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)

  • rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)

  • rsync: rsync: Authorization bypass via auth users directive parsing (CVE-2026-70463)

  • rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)

  • rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791)

  • rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)

  • rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)

  • rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)

  • rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)

  • rsync: rsync: Denial of Service via Zstandard compression thread exhaustion (CVE-2026-70455)

  • rsync: rsync: Memory corruption via out-of-bounds write in size parsing (CVE-2026-70457)

  • rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461)

  • rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802)

  • rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785)

  • rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783)

Bug Fix(es) and Enhancement(s):

  • Rebase rsync to version 3.5.0 in Rocky Linux10 (JIRA:Rocky Linux-246094)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Database specific
{
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:67463"
}
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:10 / rsync

Package

Name
rsync
Purl
pkg:rpm/rocky-linux/rsync?distro=rocky-linux-10&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0:3.5.0-3.el10_2
Database specific
Show details
{
    "yum_repository": "BaseOS"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:67463.json"