Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70460

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

A path traversal and symlink vulnerability in rsync allows a malicious sender with write access to write files outside the intended directory. By exploiting symbolic links in conjunction with the --partial-dir or --backup-dir options, an attacker can bypass path restrictions to modify arbitrary system files, compromising system integrity

Отчет

This is an Important vulnerability in rsync that allows for path traversal. Exploitation requires a malicious sender to utilize the --partial-dir or --backup-dir options and the ability to create or leverage symlinks within the rsync module's file tree. This could lead to arbitrary file writes outside the intended module root.

Меры по смягчению последствий

Disable the rsyncd daemon if it is unused (systemctl disable --now rsyncd), or strictly limit TCP/873 access to trusted clients via firewall rules. Within rsyncd.conf, block the exploit vectors directly by setting refuse options = partial-dir backup-dir and maintain defense-in-depth by enforcing use chroot = yes. Finally, ensure no root- or daemon-owned symlinks point outside your module paths, and avoid using the vulnerable flags when operating as a client against untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2515368rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
18 дней назад

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

CVSS3: 8.1
nvd
18 дней назад

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

CVSS3: 8.1
msrc
8 дней назад

rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

CVSS3: 8.1
debian
18 дней назад

rsync 2.3.3 before 3.5.0contains a path traversal vulnerability that a ...

suse-cvrf
11 дней назад

Security update for rsync

8.1 High

CVSS3