Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43619

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

A flaw was found in rsync. A local attacker with filesystem access on the daemon host can exploit a symlink race vulnerability (CWE-367 Time-of-check to time-of-use) in rsync daemons configured with 'use chroot = no'. This allows the attacker to redirect path-based system calls, such as chmod, lchown, or unlink, outside the intended module. This could lead to unauthorized file operations or other security bypasses.

Отчет

Moderate: A symlink race vulnerability affects rsync daemons when configured with use chroot = no, allowing a local attacker with filesystem access to perform unauthorized file operations outside the intended module. This risk is present only when the non-default use chroot = no setting is active.

Меры по смягчению последствий

To mitigate this issue, ensure that the rsync daemon is configured with use chroot = yes. This can be achieved by editing the rsyncd.conf file, typically located at /etc/rsyncd.conf, and setting use chroot = yes within the relevant module configuration. After modifying the configuration, the rsync service must be restarted for the changes to take effect. This may temporarily interrupt active rsync operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncOut of support scope
Red Hat Enterprise Linux 6rsyncFix deferred
Red Hat Enterprise Linux 7rsyncFix deferred
Red Hat Enterprise Linux 8rsyncFix deferred
Red Hat Enterprise Linux 9rsyncFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2469058rsync: rsync: Symlink race vulnerability allows unauthorized file operations

EPSS

Процентиль: 3%
0.00136
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
nvd
3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

CVSS3: 6.3
msrc
3 месяца назад

Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls

CVSS3: 6.3
debian
3 месяца назад

Rsync version3.4.2 and prior contain symlink race condition vulnerabil ...

CVSS3: 6.3
github
3 месяца назад

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

EPSS

Процентиль: 3%
0.00136
Низкий

6.3 Medium

CVSS3