Описание
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
A flaw was found in rsync. A local attacker with low privileges can exploit a symlink following vulnerability in the handling of input configuration files, such as those specified by --files-from or --password-file. This allows the attacker to read arbitrary files accessible to the rsync daemon process, leading to information disclosure.
Отчет
A symlink-following vulnerability in rsync allows a local, low-privileged attacker to read arbitrary files accessible to the rsync daemon. The issue occurs when rsync improperly handles input configuration files, such as --files-from or --password-file. Exploitation requires a non-default configuration where the attacker can either control the input file paths or plant symlinks within the daemon's module root.
Меры по смягчению последствий
Ensure the rsync daemon runs with the principle of least privilege, enabling use chroot = yes to securely jail the process to its module tree. Restrict write access for daemon configuration directories and files specified by --files-from or --password-file to trusted administrators only. When running rsync outside of daemon mode, ensure users only process input files originating from trusted, non-world-writable directories.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | rsync | Affected | ||
| Red Hat Enterprise Linux 7 | rsync | Affected | ||
| Red Hat Enterprise Linux 8 | rsync | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | ||
| Red Hat Enterprise Linux 10 | rsync | Fixed | RHSA-2026:67463 | 14.09.2026 |
| Red Hat Enterprise Linux 9 | rsync | Fixed | RHSA-2026:67462 | 14.09.2026 |
| Red Hat Enterprise Linux 9 | rsync | Fixed | RHSA-2026:67462 | 14.09.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
rsync before 3.5.0 contains an arbitrary file read vulnerability that ...
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с отслеживанием символьных ссылок UNIX, позволяющая нарушителю читать произвольные файлы
EPSS
7.1 High
CVSS3