Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53790

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

A command injection vulnerability in rsync allows remote attackers to execute arbitrary commands by supplying shell metacharacters or newlines in unsanitized inputs, such as hostnames or hostspecs. This impacts multiple vectors—including the RSYNC_CONNECT_PROG variable, daemon hooks, rsync-ssl, and remote-shell parsing—executing commands with the privileges of the running process or user.

Отчет

This Important vulnerability in rsync allows for remote command injection due to insufficient sanitization of user-supplied input across multiple code paths. While the attack complexity is high, successful exploitation could lead to arbitrary command execution under the privileges of the rsync process or the invoking user, impacting confidentiality, integrity, and availability. This risk is particularly relevant in environments where rsync is used for remote synchronization with untrusted sources or destinations.

Меры по смягчению последствий

Do not set RSYNC_CONNECT_PROG or pass untrusted hostnames/paths into rsync / rsync-ssl. If rsyncd is required, omit pre-xfer/post-xfer/early exec unless the command ignores client-controlled RSYNC_* values, and restrict TCP/873 to trusted clients

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2515378rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
24 дня назад

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

CVSS3: 8.1
nvd
24 дня назад

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

msrc
14 дней назад

rsync < 3.5.0 Command Injection via Multiple Code Paths

CVSS3: 8.1
debian
24 дня назад

rsync before 3.5.0contains multiple command and argument injection vul ...

suse-cvrf
17 дней назад

Security update for rsync

8.1 High

CVSS3