Описание
ELSA-2026-19368: rsync security update (IMPORTANT)
[3.2.5-7.2]
- Fix integer overflow in compressed-token decoding (CVE-2026-43618)
- Resolves: RHEL-174932
[3.2.5-7.1]
- Fix TOCTOU symlink race in daemon no-chroot mode (CVE-2026-29518)
- Resolves: RHEL-174952
[3.2.5-4]
- Resolves: RHEL-104404 - Do not clear DISPLAY unconditionally
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
rsync
3.2.5-7.el9_8.2
rsync-daemon
3.2.5-7.el9_8.2
rsync-rrsync
3.2.5-7.el9_8.2
Oracle Linux x86_64
rsync
3.2.5-7.el9_8.2
rsync-daemon
3.2.5-7.el9_8.2
rsync-rrsync
3.2.5-7.el9_8.2
Связанные CVE
Связанные уязвимости
CVSS3: 7.4
ubuntu
4 месяца назад
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.