Описание
ELSA-2026-19152: rsync security update (IMPORTANT)
[3.4.4-1]
- Resolves: RHEL-181630 - Rebase rsync to version 3.4.4
- Resolves: RHEL-174929 - TOCTOU symlink race condition (CVE-2026-29518)
- Resolves: RHEL-174949 - Memory disclosure via int overflow (CVE-2026-43618)
[3.4.1-3]
- Resolves: RHEL-118549 - Do not clear DISPLAY unconditionally
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
rsync-daemon
3.4.4-1.el10_2
rsync-rrsync
3.4.4-1.el10_2
rsync
3.4.4-1.el10_2
Oracle Linux x86_64
rsync-daemon
3.4.4-1.el10_2
rsync-rrsync
3.4.4-1.el10_2
rsync
3.4.4-1.el10_2
Связанные CVE
Связанные уязвимости
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted len ...