Description:
The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.
Security Fix(es):
* rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
* rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454)
* rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
* rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
* rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
* rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
* rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
* rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
* rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
* rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
* rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791)
* rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
* rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
* rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)
* rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)
* rsync: rsync: Memory corruption via out-of-bounds write in size parsing (CVE-2026-70457)
* rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461)
* rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802)
* rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785)
* rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783)
Bug Fix(es) and Enhancement(s):
* Rebase rsync to version 3.2.7 in AlmaLinux9 (JIRA:AlmaLinux-248835)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
rsync-3.2.7-1.el9_8.aarch64.rpm |
d64f74585c840f81b4932d45f3922538a445315bbfa1175b93bc9f799eb755cc |
| noarch |
rsync-rrsync-3.2.7-1.el9_8.noarch.rpm |
7d9a830ad81c396036b02e9fde77cacde85572516743db30575017ec1b4f4802 |
| noarch |
rsync-daemon-3.2.7-1.el9_8.noarch.rpm |
b5d900802bfdefae90bb876bbf3f550bd65797f89a787ceb8668bb274765fd7c |
| ppc64le |
rsync-3.2.7-1.el9_8.ppc64le.rpm |
cfac8b311043cdef13dc8fe6812dd173dc89b052a4a0d5d1ede197770f0c6299 |
| s390x |
rsync-3.2.7-1.el9_8.s390x.rpm |
37173fbff9aedb5eeb487bb029a48a41813300c04c17d3635a6c6432e9b5a8ee |
| x86_64 |
rsync-3.2.7-1.el9_8.x86_64.rpm |
20cc9871b5fbffabf75442fb2960805995dfd0eba60cad79996460d0fe35ae08 |