Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19152

Опубликовано: 17 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-19152: rsync security update (IMPORTANT)

[3.4.4-1]

  • Resolves: RHEL-181630 - Rebase rsync to version 3.4.4
  • Resolves: RHEL-174929 - TOCTOU symlink race condition (CVE-2026-29518)
  • Resolves: RHEL-174949 - Memory disclosure via int overflow (CVE-2026-43618)

[3.4.1-3]

  • Resolves: RHEL-118549 - Do not clear DISPLAY unconditionally

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

rsync-daemon

3.4.4-1.el10_2

rsync-rrsync

3.4.4-1.el10_2

rsync

3.4.4-1.el10_2

Oracle Linux x86_64

rsync-daemon

3.4.4-1.el10_2

rsync-rrsync

3.4.4-1.el10_2

rsync

3.4.4-1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
redhat
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

CVSS3: 7.4
nvd
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted len ...