Количество 16
Количество 16
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ...
GHSA-pfv9-gp3h-73xv
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
RLSA-2026:26410
Important: rsync security update
RLSA-2026:26408
Important: rsync security update
RLSA-2026:26332
Important: rsync security, bug fix, and enhancement update
ELSA-2026-26410
ELSA-2026-26410: rsync security update (IMPORTANT)
ELSA-2026-26408
ELSA-2026-26408: rsync security update (IMPORTANT)
ELSA-2026-26332
ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT)
openSUSE-SU-2026:20877-1
Security update for rsync
SUSE-SU-2026:2083-1
Security update for rsync
SUSE-SU-2026:2048-1
Security update for rsync
SUSE-SU-2026:2038-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ... | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
GHSA-pfv9-gp3h-73xv Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
RLSA-2026:26410 Important: rsync security update | около 2 месяцев назад | |||
RLSA-2026:26408 Important: rsync security update | около 2 месяцев назад | |||
RLSA-2026:26332 Important: rsync security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-26410 ELSA-2026-26410: rsync security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-26408 ELSA-2026-26408: rsync security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-26332 ELSA-2026-26332: rsync security, bug fix, and enhancement update (IMPORTANT) | 17 дней назад | |||
openSUSE-SU-2026:20877-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2083-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2048-1 Security update for rsync | 2 месяца назад | |||
SUSE-SU-2026:2038-1 Security update for rsync | 2 месяца назад |
Уязвимостей на страницу