<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:09:02.307830+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67462</id>
    <title>ALSA-2026:67462 — Important: rsync security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:09:02.329285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: rsync, AlmaLinux:9: rsync-daemon, AlmaLinux:9: rsync-rrsync</p>
<p>The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.</p>
<p>Security Fix(es):</p>
<p>* rsync: rsync 2.3.3 &lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
  * rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454)
  * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
  * rsync: rsync &lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
  * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
  * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
  * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
  * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
  * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
  * rsync: rsync 3.1.0 &lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
  * rsync: rsync &lt; 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791)
  * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
  * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
  * rsync: rsync &lt; 3.5.0 Path Confinemen…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14714</id>
    <title>bdu:2026-14714</title>
    <updated>2026-10-02T19:09:02.329368+00:00</updated>
    <content>bdu:2026-14714</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-70464</id>
    <title>BELL-CVE-2026-70464</title>
    <updated>2026-10-02T19:09:02.329386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-70464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352711</id>
    <title>EUVD-2026-352711</title>
    <updated>2026-10-02T19:09:02.329407+00:00</updated>
    <content>EUVD-2026-352711</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352711"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-70464</id>
    <title>fkie_cve-2026-70464</title>
    <updated>2026-10-02T19:09:02.329419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-70464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-70464</id>
    <title>msrc_CVE-2026-70464 — rsync 2.0.0 &lt; 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall</title>
    <updated>2026-10-02T19:09:02.329442+00:00</updated>
    <content>msrc_CVE-2026-70464</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-70464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3949</id>
    <title>OESA-2026-3949 — rsync security update</title>
    <updated>2026-10-02T19:09:02.329459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: rsync</p>
<p>Rsync is an open source utility that provides fast incremental file transfer. It uses the &amp;amp;quot;rsync algorithm&amp;amp;quot; which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand.

Security Fix(es):</p>
<p>Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with &amp;apos;use chroot = no&amp;apos;.(CVE-2026-43619)</p>
<p>rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11869-1</id>
    <title>openSUSE-SU-2026:11869-1 — rsync-3.5.1-1.1 on GA media</title>
    <updated>2026-10-02T19:09:02.329545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync-3.5.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11869-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71446</id>
    <title>RHSA-2026:71446 — Red Hat Security Advisory: OpenShift Container Platform 4.22.16 bug fix and security update</title>
    <updated>2026-10-02T19:09:02.329590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl: Perl: Incorrect regular expression processing via large regular expressions rsync: rsync: Unauthorized File Access via Symlink Module Root rsync: rsync: Arbitrary file write via path traversal in --relative mode rsync: rsync: Arbitrary file deletion via malicious file list rsync: rsync &lt; 3.5.0 Command Injection via Multiple Code Paths rsync: rsync &lt; 3.5.0 Daemon IP Spoofing via PROXY Protocol Header rsync: rsync &lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options rsync: rsync: Arbitrary File Read via Symlink Following rsync: rsync: Local Privilege Escalation via Symlink Following rsync: rsync 3.1.0 &lt; 3.5.0 Access Control Bypass via DNS Resolution Failure rsync: rsync: Denial of Service via Algorithmic Complexity rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions rsync: rsync: Heap Out-of-Bounds Write via crafted argument list rsync: rsync: Memory corruption via out-of-bounds write in size parsing rsync: rsync: Memory corruption via crafted file entries rsync: rsync 2.3.3 &lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink rsync: rsync: Information disclosure and denial of service via crafted files-from entry rsync: rsync: Authorization bypass via `auth users` directive parsing rsync: rsync: Denial of Service via handshake stall</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67462</id>
    <title>RLSA-2026:67462 — Important: rsync security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:09:02.329643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: rsync</p>
<p>The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.</p>
<p>Security Fix(es):</p>
<p>* rsync: rsync 2.3.3 &lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)</p>
<p>* rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions (CVE-2026-70454)</p>
<p>* rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)</p>
<p>* rsync: rsync &lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)</p>
<p>* rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)</p>
<p>* rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)</p>
<p>* rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)</p>
<p>* rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)</p>
<p>* rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)</p>
<p>* rsync: rsync 3.1.0 &lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)</p>
<p>* rsync: rsync &lt; 3.5.0 Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791)</p>
<p>* rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)</p>
<p>* rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)</p>
<p>* rsync: rsync &lt; 3.5.0 Path Confinement Bypass via /./ Bo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23253-1</id>
    <title>SUSE-SU-2026:23253-1 — Security update for rsync</title>
    <updated>2026-10-02T19:09:02.329687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rsync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23253-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-70464</id>
    <title>UBUNTU-CVE-2026-70464</title>
    <updated>2026-10-02T19:09:02.329719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:26.04:LTS: rsync</p>
<p>rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-70464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2817</id>
    <title>WID-SEC-W-2026-2817 — Rsync: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:09:02.329746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten offenzulegen oder zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2817"/>
  </entry>
</feed>
