Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53784

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.1

Описание

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.

A flaw was found in rsync. This path traversal vulnerability allows remote clients to access files outside the intended module root. This occurs when the use chroot option is disabled and the module root path, or a component of it, is a symbolic link. The rsync daemon fails to resolve symlinks during session initialization, causing subsequent operations to reference files relative to the symlink target, leading to unauthorized file access.

Отчет

This is an Important flaw. The rsync daemon is vulnerable to unauthorized file access via path traversal when configured with a symlinked module root and the use chroot option is explicitly disabled. This configuration is not default, but if present, a local attacker with low privileges could exploit this to read or write files outside the intended module root.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that the use chroot option is enabled in the rsync daemon configuration. If use chroot cannot be enabled, avoid using symlinks as the module root path or any of its components in the rsync daemon configuration. After modifying the rsync configuration, restart the rsync service for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2515384rsync: rsync: Unauthorized File Access via Symlink Module Root

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
24 дня назад

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.

CVSS3: 7.1
nvd
24 дня назад

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.

msrc
14 дней назад

rsync < 3.5.0 Path Traversal via Symlink Module Root

CVSS3: 7.1
debian
24 дня назад

rsync before 3.5.0contains a path traversal vulnerability that allows ...

suse-cvrf
17 дней назад

Security update for rsync

7.1 High

CVSS3