[ALSA-2026:67463] Important: rsync security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-09-15
Description:
The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): * rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460) * rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454) * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789) * rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790) * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458) * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464) * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803) * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784) * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463) * rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452) * rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791) * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795) * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456) * rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793) * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453) * rsync: rsync: Denial of Service via Zstandard compression thread exhaustion (CVE-2026-70455) * rsync: rsync: Memory corruption via out-of-bounds write in size parsing (CVE-2026-70457) * rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461) * rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802) * rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785) * rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783) Bug Fix(es) and Enhancement(s): * Rebase rsync to version 3.5.0 in AlmaLinux10 (JIRA:AlmaLinux-246094) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 rsync-3.5.0-3.el10_2.aarch64.rpm 083a290c8202305d7e47d055fce15fb023be49dd11e0bab9a828988db93b52ee
noarch rsync-daemon-3.5.0-3.el10_2.noarch.rpm d9eeb4e538648566b7bc50ebdf47325f2158a1f110be3d5a1451d1dbf7b786e9
noarch rsync-rrsync-3.5.0-3.el10_2.noarch.rpm f379c5d18d7e720110d224d854c2e2796f7af861e7e3c5b78903eaadc9caa299
ppc64le rsync-3.5.0-3.el10_2.ppc64le.rpm 8654b7583b806337409240ce727bcd41adedcc97e6eb305c3ce04b38826def2f
s390x rsync-3.5.0-3.el10_2.s390x.rpm 39240c9c0662b4acb4eaa7d3e3ea648d4990ae2fbfd1dc1f5e8a3f36a96f925c
x86_64 rsync-3.5.0-3.el10_2.x86_64.rpm 8864f24ffcc60c5004508e69d03535a21b2298996b82f06914f212576acada0d
x86_64_v2 rsync-3.5.0-3.el10_2.x86_64_v2.rpm 0ef43712db75150af848c2d4b7c0bf5afed44360f9c1e5232140fc0d819ddedf
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.