[CLSA-2026:1779462894] rsync: Fix of CVE-2026-43620
Type:
security
Severity:
Moderate
Release date:
2026-05-22 15:14:59 UTC
Description:
- CVE-2026-43620: prevent client-side out-of-bounds read in receiver when a malicious server sends a crafted file-list with parent_ndx<0
Updated packages:
  • rsync-3.2.3-19.el9_2.tuxcare.els6.x86_64.rpm
    sha:a15b8ca272f64aeaa61c931428a63494826a80b3aa0134c2f9a56d2b65063c43
  • rsync-daemon-3.2.3-19.el9_2.tuxcare.els6.noarch.rpm
    sha:b4b0690d1ef18edbe02431aae87401417bed3119601622152336caa7167d46c5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.