Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19368

Опубликовано: 29 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-19368: rsync security update (IMPORTANT)

[3.2.5-7.2]

  • Fix integer overflow in compressed-token decoding (CVE-2026-43618)
  • Resolves: RHEL-174932

[3.2.5-7.1]

  • Fix TOCTOU symlink race in daemon no-chroot mode (CVE-2026-29518)
  • Resolves: RHEL-174952

[3.2.5-4]

  • Resolves: RHEL-104404 - Do not clear DISPLAY unconditionally

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

rsync

3.2.5-7.el9_8.2

rsync-daemon

3.2.5-7.el9_8.2

rsync-rrsync

3.2.5-7.el9_8.2

Oracle Linux x86_64

rsync

3.2.5-7.el9_8.2

rsync-daemon

3.2.5-7.el9_8.2

rsync-rrsync

3.2.5-7.el9_8.2

Связанные CVE

Связанные уязвимости

rocky
2 месяца назад

Important: rsync security update

suse-cvrf
2 месяца назад

Security update for rsync

suse-cvrf
2 месяца назад

Security update for rsync

suse-cvrf
2 месяца назад

Security update for rsync

CVSS3: 7.4
ubuntu
4 месяца назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.