Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2002-1

Опубликовано: 19 мая 2026
Источник: suse-cvrf

Описание

Security update for rsync

This update for rsync fixes the following issue

  • CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223).

Список пакетов

Image SLES12-SP5-Azure-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-Standard-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-ECS-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-SAP-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-SAP-On-Demand
rsync-3.1.3-3.40.1
SUSE Linux Enterprise Server 12 SP5-LTSS
rsync-3.1.3-3.40.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
rsync-3.1.3-3.40.1

Описание

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-BYOS:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-On-Demand:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-BYOS:rsync-3.1.3-3.40.1

Ссылки