Описание
Security update for rsync
This update for rsync fixes the following issue
- CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223).
Список пакетов
Image SLES12-SP5-Azure-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-Standard-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-ECS-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-EC2-SAP-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-On-Demand
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-SAP-BYOS
rsync-3.1.3-3.40.1
Image SLES12-SP5-GCE-SAP-On-Demand
rsync-3.1.3-3.40.1
SUSE Linux Enterprise Server 12 SP5-LTSS
rsync-3.1.3-3.40.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
rsync-3.1.3-3.40.1
Ссылки
- Link for SUSE-SU-2026:2002-1
- E-Mail link for SUSE-SU-2026:2002-1
- SUSE Security Ratings
- SUSE Bug 1262223
- SUSE CVE CVE-2026-41035 page
Описание
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.
Затронутые продукты
Image SLES12-SP5-Azure-BYOS:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-BYOS:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-HPC-On-Demand:rsync-3.1.3-3.40.1
Image SLES12-SP5-Azure-SAP-BYOS:rsync-3.1.3-3.40.1
Ссылки
- CVE-2026-41035
- SUSE Bug 1262223