Количество 13
Количество 13
GHSA-pfv9-gp3h-73xv
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-29518
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ...
RLSA-2026:26410
Important: rsync security update
RLSA-2026:26408
Important: rsync security update
ELSA-2026-26408
ELSA-2026-26408: rsync security update (IMPORTANT)
openSUSE-SU-2026:20877-1
Security update for rsync
SUSE-SU-2026:2083-1
Security update for rsync
SUSE-SU-2026:2048-1
Security update for rsync
SUSE-SU-2026:2038-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pfv9-gp3h-73xv Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
CVE-2026-29518 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TO ... | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
RLSA-2026:26410 Important: rsync security update | 3 месяца назад | |||
RLSA-2026:26408 Important: rsync security update | 3 месяца назад | |||
ELSA-2026-26408 ELSA-2026-26408: rsync security update (IMPORTANT) | 3 месяца назад | |||
openSUSE-SU-2026:20877-1 Security update for rsync | 4 месяца назад | |||
SUSE-SU-2026:2083-1 Security update for rsync | 4 месяца назад | |||
SUSE-SU-2026:2048-1 Security update for rsync | 4 месяца назад | |||
SUSE-SU-2026:2038-1 Security update for rsync | 4 месяца назад |
Уязвимостей на страницу