Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53802

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.

A flaw was found in rsync. A local attacker with low privileges can exploit a symlink following vulnerability in the handling of input configuration files, such as those specified by --files-from or --password-file. This allows the attacker to read arbitrary files accessible to the rsync daemon process, leading to information disclosure.

Отчет

A symlink-following vulnerability in rsync allows a local, low-privileged attacker to read arbitrary files accessible to the rsync daemon. The issue occurs when rsync improperly handles input configuration files, such as --files-from or --password-file. Exploitation requires a non-default configuration where the attacker can either control the input file paths or plant symlinks within the daemon's module root.

Меры по смягчению последствий

Ensure the rsync daemon runs with the principle of least privilege, enabling use chroot = yes to securely jail the process to its module tree. Restrict write access for daemon configuration directories and files specified by --files-from or --password-file to trusted administrators only. When running rsync outside of daemon mode, ensure users only process input files originating from trusted, non-world-writable directories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Enterprise Linux 10rsyncFixedRHSA-2026:6746314.09.2026
Red Hat Enterprise Linux 9rsyncFixedRHSA-2026:6746214.09.2026
Red Hat Enterprise Linux 9rsyncFixedRHSA-2026:6746214.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2515416rsync: rsync: Arbitrary File Read via Symlink Following

EPSS

Процентиль: 15%
0.00238
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 месяца назад

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.

CVSS3: 7.1
nvd
около 1 месяца назад

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.

msrc
28 дней назад

rsync < 3.5.0 Arbitrary File Read via Symlink Following

CVSS3: 7.1
debian
около 1 месяца назад

rsync before 3.5.0 contains an arbitrary file read vulnerability that ...

CVSS3: 7.1
fstec
около 1 месяца назад

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с отслеживанием символьных ссылок UNIX, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 15%
0.00238
Низкий

7.1 High

CVSS3