Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53798

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*
Версия до 3.5.0 (исключая)

EPSS

Процентиль: 20%
0.00278
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 5.3
ubuntu
24 дня назад

rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.

msrc
14 дней назад

rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping

CVSS3: 5.3
debian
24 дня назад

rsync before 3.5.0contains a privilege confusion vulnerability in the ...

suse-cvrf
17 дней назад

Security update for rsync

suse-cvrf
19 дней назад

Security update for rsync

EPSS

Процентиль: 20%
0.00278
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-704