Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-17481

Опубликовано: 14 мая 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-17481: rsync security update (IMPORTANT)

[3.1.3-25]

  • Resolves: RHEL-169141 - CVE-2026-41035 - Use-after-free vulnerability in extended attribute handling

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

rsync

3.1.3-25.el8_10

rsync-daemon

3.1.3-25.el8_10

Oracle Linux x86_64

rsync

3.1.3-25.el8_10

rsync-daemon

3.1.3-25.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
redhat
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
nvd
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted len ...