Количество 7
Количество 7
CVE-2026-53799
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.
CVE-2026-53799
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.
CVE-2026-53799
rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application
CVE-2026-53799
rsync before 3.5.0contains a symlink race condition vulnerability that ...
SUSE-SU-2026:3657-1
Security update for rsync
SUSE-SU-2026:3634-1
Security update for rsync
openSUSE-SU-2026:21650-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53799 rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation. | CVSS3: 6.3 | 0% Низкий | 24 дня назад | |
CVE-2026-53799 rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation. | CVSS3: 6.3 | 0% Низкий | 24 дня назад | |
CVE-2026-53799 rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application | 0% Низкий | 14 дней назад | ||
CVE-2026-53799 rsync before 3.5.0contains a symlink race condition vulnerability that ... | CVSS3: 6.3 | 0% Низкий | 24 дня назад | |
SUSE-SU-2026:3657-1 Security update for rsync | 17 дней назад | |||
SUSE-SU-2026:3634-1 Security update for rsync | 19 дней назад | |||
openSUSE-SU-2026:21650-1 Security update for rsync | 11 дней назад |
Уязвимостей на страницу