[CLSA-2026:1791385859] rsync: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-08 22:28:59 UTC
Description:
- CVE-2026-53802: open the daemon secrets file, the client --password-file, --files-from and the --filter merge / per-directory merge files refusing attacker-planted symlinks -- confined beneath the module root on a daemon, owner-trust walk otherwise; getpassf() fstat()s the opened fd, not the path
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els17.i686.rpm
    sha:1c408e5ae8ce296c798e6aea8e1961f5b8b755864fffc4096181a1f8315de217
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els17.x86_64.rpm
    sha:97b9ded4f52cb7cf51fae15fefa57ab0b633a3fe22d24e90cfe6c8b4273ff4e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.