Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53800

Опубликовано: 13 авг. 2026
Источник: debian

Описание

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyncfixed3.5.0+ds1-1package

Примечания

  • https://download.samba.org/pub/rsync/NEWS#3.5.0

Связанные уязвимости

CVSS3: 4.7
ubuntu
24 дня назад

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.

CVSS3: 4.7
nvd
24 дня назад

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.

msrc
14 дней назад

rsync < 3.5.0 Symlink Race Condition via --remove-source-files

suse-cvrf
17 дней назад

Security update for rsync

suse-cvrf
19 дней назад

Security update for rsync