[CLSA-2026:1791385437] rsync: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-08 23:02:39 UTC
Description:
- CVE-2026-53802: open the daemon secrets file, the client --password-file, --files-from and the --filter merge / per-directory merge files refusing attacker-planted symlinks -- confined beneath the module root on a daemon, owner-trust walk otherwise; getpassf() fstat()s the opened fd, not the path
Updated packages:
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els17.aarch64.rpm
    sha:05ce8889fd06e7019f5f16e68800f8912f438d89b7b7281cbc279f7473612b62
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els17.i686.rpm
    sha:38f4784a45f1cbc9d36810a1f5959a39ecd0b5cda78808013a3fc0008f273c9e
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els17.x86_64.rpm
    sha:982a165d1b0920d147fb4e10f0692cdaec35eaf63d83fd6fa7c31297852ed4b0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.