Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:19368

Опубликовано: 28 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: rsync security update

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

  • rsync: rsync server leaks arbitrary client files (CVE-2024-12086)

  • rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
rsyncx86_647.el9_8rsync-3.2.5-7.el9_8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
3 месяца назад

ELSA-2026-19368: rsync security update (IMPORTANT)

suse-cvrf
4 месяца назад

Security update for rsync

suse-cvrf
4 месяца назад

Security update for rsync

suse-cvrf
4 месяца назад

Security update for rsync

CVSS3: 7.4
ubuntu
5 месяцев назад

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.