Medium severity5.3NVD Advisory· Published Aug 13, 2026· Updated Aug 31, 2026
CVE-2026-53798
CVE-2026-53798
Description
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/RsyncProject/rsync/security/advisories/GHSA-hx7p-3gvv-pqgvnvdVendor Advisory
- www.vulncheck.com/advisories/rsync-privilege-confusion-via-name-converter-uid-gid-mappingnvdRelease NotesThird Party Advisory
- github.com/RsyncProject/rsync/releases/tag/v3.5.0nvdProductRelease Notes
News mentions
1- Rsync: 25 Vulnerabilities Disclosed Together, Affecting Versions Before 3.5.0Vypr Intelligence · Aug 13, 2026