Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-6825

Опубликовано: 07 апр. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-6825: rsync security update (MODERATE)

[3.4.1-2.2]

  • Resolves: RHEL-152885 - CVE-2025-10158 Out of bounds array access via negative index

[3.4.1-2.1]

  • Resolves: RHEL-152878 - clearing DISPLAY breaks SSH_ASKPASS expectations

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

rsync

3.4.1-2.el10_1.2

rsync-daemon

3.4.1-2.el10_1.2

rsync-rrsync

3.4.1-2.el10_1.2

Oracle Linux x86_64

rsync

3.4.1-2.el10_1.2

rsync-daemon

3.4.1-2.el10_1.2

rsync-rrsync

3.4.1-2.el10_1.2

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
8 месяцев назад

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVSS3: 4.3
redhat
8 месяцев назад

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVSS3: 4.3
nvd
8 месяцев назад

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVSS3: 5.4
msrc
8 месяцев назад

Rsync: Out of bounds array access via negative index

CVSS3: 4.3
debian
8 месяцев назад

A malicious client acting as the receiver of an rsync file transfer ca ...