[CLSA-2026:1779694887] rsync: Fix of CVE-2026-29518
Type:
security
Severity:
Important
Release date:
2026-05-25 07:41:30 UTC
Description:
- CVE-2026-29518: fix daemon-no-chroot TOCTOU symlink race by tracking per-module chroot in am_chrooted, routing sender read-path, receiver basis-file open, mkstemp, and inplace write through secure_relative_open() / secure_mkstemp()
Updated packages:
  • rsync-3.1.3-12.el8.tuxcare.els11.x86_64.rpm
    sha:f02618dc7e086d99e60027925f74a773082bb92ead9b3510a62aa984dda58afd
  • rsync-daemon-3.1.3-12.el8.tuxcare.els11.noarch.rpm
    sha:80a324abd94ea4db1618c5ca953bc7fcfd1c43e285379e4c835b933521312d5d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.