Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53803

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7

Описание

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.

A symlink-following vulnerability in rsync allows local attackers to redirect predictable output paths to arbitrary filesystem locations. When rsync runs with elevated privileges (such as setuid or a privileged daemon), this enables arbitrary file overwrites and local privilege escalation.

Отчет

This Important vulnerability in rsync allows a local attacker to achieve privilege escalation by exploiting a symlink following flaw. In Red Hat environments, the risk is elevated when rsync is configured to run with elevated privileges, such as setuid or in daemon mode, enabling an attacker to overwrite arbitrary files. The requirement for local access and specific privileged configurations prevents a Critical impact.

Меры по смягчению последствий

Do not run rsync setuid or point output paths (--log-file, --write-batch, or daemon config/log files) to user-writable directories like /tmp. While fs.protected_symlinks=1 prevents simple symlink creation in sticky directories on RHEL 7+, it does not stop parent-component attacks in standard directories. If the rsyncd daemon is unneeded, disable it (systemctl disable --now rsyncd); if required, enforce least-privilege execution and restrict network access to trusted hosts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2515381rsync: rsync: Local Privilege Escalation via Symlink Following

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
24 дня назад

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.

CVSS3: 7.8
nvd
24 дня назад

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.

msrc
14 дней назад

rsync < 3.5.0 Symlink Following Arbitrary File Overwrite

CVSS3: 7.8
debian
24 дня назад

rsync before 3.5.0 contains a symlink following vulnerability that all ...

suse-cvrf
17 дней назад

Security update for rsync

7 High

CVSS3