Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53791

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.4

Описание

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.

A flaw in rsync allows an unauthenticated remote attacker to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source IP address, granting unauthorized access to restricted resources.

Отчет

A flaw was found in the rsync daemon. When configured to use the PROXY protocol, an unauthenticated remote attacker can bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source IP address. This allows unauthorized access to restricted resources. Note: Red Hat Enterprise Linux 8 and earlier versions do not contain the vulnerable PROXY protocol implementation and are not affected.

Меры по смягчению последствий

Restrict rsync daemon TCP/873 to the trusted proxy only (CME-202). If PROXY protocol is unused, leave proxy protocol disabled (the default).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncNot affected
Red Hat Enterprise Linux 8rsyncNot affected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2515387rsync: rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
24 дня назад

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.

CVSS3: 9.1
nvd
24 дня назад

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.

msrc
14 дней назад

rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

CVSS3: 9.1
debian
24 дня назад

rsync daemon before 3.5.0contains an IP address spoofing vulnerability ...

suse-cvrf
17 дней назад

Security update for rsync

7.4 High

CVSS3