rpm package
opensuse/rsync&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2016.0
Vulnerabilities (41)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-53796 | Med | 6.3 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locatio | |
| CVE-2026-53795 | Hig | 8.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve t | |
| CVE-2026-53794 | Med | 5.3 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbou | |
| CVE-2026-53793 | Hig | 7.4 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can ex | |
| CVE-2026-53792 | Med | 6.5 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send | |
| CVE-2026-53791 | Cri | 9.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon | |
| CVE-2026-53790 | Hig | 8.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapp | |
| CVE-2026-53789 | Med | 6.5 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or | |
| CVE-2026-53788 | Med | 6.5 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters in | |
| CVE-2026-53786 | Med | 6.5 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to | |
| CVE-2026-53785 | Hig | 7.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outsi | |
| CVE-2026-53784 | Hig | 7.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session in | |
| CVE-2026-53783 | Hig | 8.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Aug 13, 2026 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but | |
| CVE-2026-44510 | — | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. | ||
| CVE-2026-44509 | — | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. | ||
| CVE-2026-44508 | — | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. | ||
| CVE-2026-44507 | — | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users should reference CVE-2026-43617 instead of this candidate. | ||
| CVE-2026-43620 | Med | 6.5 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | May 20, 2026 | Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility fl | |
| CVE-2026-43619 | Med | 6.3 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | May 20, 2026 | Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported r | |
| CVE-2026-43618 | Hig | 8.1 | < 3.4.1-160000.6.1 | 3.4.1-160000.6.1 | May 20, 2026 | Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outs |
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locatio
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve t
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbou
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can ex
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapp
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters in
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outsi
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session in
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but
- CVE-2026-44510Jul 20, 2026affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.
- CVE-2026-44509Jul 20, 2026affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.
- CVE-2026-44508Jul 20, 2026affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.
- CVE-2026-44507Jul 20, 2026affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users should reference CVE-2026-43617 instead of this candidate.
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility fl
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported r
- affected < 3.4.1-160000.6.1fixed 3.4.1-160000.6.1
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outs
Page 2 of 3