Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53797

Опубликовано: 13 авг. 2026
Источник: debian

Описание

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path resolution and file open operations to disclose file contents outside the intended transfer root.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.5.0+ds1-1package

Примечания

  • https://download.samba.org/pub/rsync/NEWS#3.5.0

Связанные уязвимости

CVSS3: 4.7
ubuntu
24 дня назад

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path resolution and file open operations to disclose file contents outside the intended transfer root.

CVSS3: 4.7
nvd
24 дня назад

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory of the source tree to redirect file reads to unintended paths. Attackers can atomically replace a parent directory component with a symlink pointing outside the source root between path resolution and file open operations to disclose file contents outside the intended transfer root.

msrc
14 дней назад

rsync < 3.5.0 Symlink Race Condition Information Disclosure

suse-cvrf
17 дней назад

Security update for rsync

suse-cvrf
19 дней назад

Security update for rsync