Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2083-1

Опубликовано: 27 мая 2026
Источник: suse-cvrf

Описание

Security update for rsync

This update for rsync fixes the following issues

  • CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511).
  • CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223).
  • CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515).
  • CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512).
  • CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513).
  • CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296).

Список пакетов

Container suse/sle-micro-rancher/5.3:latest
rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest
rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest
rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest
rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/kvm-5.5:latest
rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/rt-5.5:latest
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-BYOS
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-BYOS
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-HPC-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-Hardened-BYOS
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-Hardened-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-Hardened-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-Hardened-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-BYOS
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-BYOS
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAP-Hardened-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAPCAL
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAPCAL-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAPCAL-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP4-SAPCAL-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Azure-3P
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Azure-Basic
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Azure-Standard
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-HPC-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-HPC-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-HPC-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-HPC-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Hardened-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Hardened-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-Hardened-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Azure-3P
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Hardened-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAP-Hardened-GCE
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAPCAL-Azure
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAPCAL-EC2
rsync-3.2.3-150400.3.31.1
Image SLES15-SP5-SAPCAL-GCE
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Micro 5.3
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Micro 5.4
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Micro 5.5
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Server 15 SP4-LTSS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Server 15 SP5-LTSS
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
rsync-3.2.3-150400.3.31.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
rsync-3.2.3-150400.3.31.1

Описание

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a specially crafted file list where the first sorted entry is not the leading dot directory, followed by a transfer record with ndx=0 and an iflag word without ITEM_TRANSFER, causing the receiver to read 8 bytes before the allocated pointer array and dereference an invalid pointer at an unmapped address, resulting in a deterministic SIGSEGV crash of the rsync client.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки

Описание

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro-rancher/5.4:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/5.5:latest:rsync-3.2.3-150400.3.31.1
Container suse/sle-micro/base-5.5:latest:rsync-3.2.3-150400.3.31.1

Ссылки