Количество 13
Количество 13
CVE-2026-53783
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.
CVE-2026-53783
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.
CVE-2026-53783
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.
CVE-2026-53783
rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync
CVE-2026-53783
rsync before3.5.0 contains a time-of-check to time-of-use (TOCTOU) rac ...
BDU:2026-14819
Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю обойти существующие ограничения безопасности
RLSA-2026:67462
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67462-0
ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:67463
Important: rsync security, bug fix, and enhancement update
ELSA-2026-67463-0
ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3657-1
Security update for rsync
SUSE-SU-2026:3634-1
Security update for rsync
openSUSE-SU-2026:21650-1
Security update for rsync
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53783 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53783 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53783 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-53783 rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync | 0% Низкий | 28 дней назад | ||
CVE-2026-53783 rsync before3.5.0 contains a time-of-check to time-of-use (TOCTOU) rac ... | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
BDU:2026-14819 Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю обойти существующие ограничения безопасности | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:67462 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67462-0 ELSA-2026-67462-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
RLSA-2026:67463 Important: rsync security, bug fix, and enhancement update | 5 дней назад | |||
ELSA-2026-67463-0 ELSA-2026-67463-0: rsync security, bug fix, and enhancement update (IMPORTANT) | 5 дней назад | |||
SUSE-SU-2026:3657-1 Security update for rsync | около 1 месяца назад | |||
SUSE-SU-2026:3634-1 Security update for rsync | около 1 месяца назад | |||
openSUSE-SU-2026:21650-1 Security update for rsync | 25 дней назад |
Уязвимостей на страницу