<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:19 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-53796</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-53796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-53796</guid>
    </item>
    <item>
      <title>EUVD-2026-352617</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352617</link>
      <description>EUVD-2026-352617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352617</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53796</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53796</link>
      <description>&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver&amp;#39;s destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Attackers can substitute a symlink for a component of the destination path between the path resolution and chdir() call, causing the receiver&amp;#39;s working directory to be established outside the intended destination tree so that subsequent relative-path file writes land in unintended filesystem locations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver&amp;#39;s destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Attackers can substitute a symlink for a component of the destination path between the path resolution and chdir() call, causing the receiver&amp;#39;s working directory to be established outside the intended destination tree so that subsequent relative-path file writes land in unintended filesystem locations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53796</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-53796 — rsync &lt; 3.5.0 TOCTOU Race Condition via Destination Directory Handling</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53796</link>
      <description>msrc_CVE-2026-53796</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-53796</guid>
    </item>
    <item>
      <title>OESA-2026-3949 — rsync security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: rsync&lt;/p&gt;
&lt;p&gt;Rsync is an open source utility that provides fast incremental file transfer. It uses the &amp;amp;amp;quot;rsync algorithm&amp;amp;amp;quot; which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with &amp;amp;apos;use chroot = no&amp;amp;apos;.(CVE-2026-43619)&lt;/p&gt;
&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: rsync&lt;/p&gt;
&lt;p&gt;Rsync is an open source utility that provides fast incremental file transfer. It uses the &amp;amp;amp;quot;rsync algorithm&amp;amp;amp;quot; which provides a very fast method for bringing remote files into sync. It does this by sending just the differences in the files across the link, without requiring that both sets of files are present at one of the ends of the link beforehand.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with &amp;amp;apos;use chroot = no&amp;amp;apos;.(CVE-2026-43619)&lt;/p&gt;
&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3949</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11869-1 — rsync-3.5.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11869-1</link>
      <description>&lt;p&gt;rsync-3.5.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rsync-3.5.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11869-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23253-1 — Security update for rsync</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23253-1</link>
      <description>&lt;p&gt;Security update for rsync&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rsync&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23253-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-53796</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:26.04:LTS: rsync&lt;/p&gt;
&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver&amp;#39;s destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Attackers can substitute a symlink for a component of the destination path between the path resolution and chdir() call, causing the receiver&amp;#39;s working directory to be established outside the intended destination tree so that subsequent relative-path file writes land in unintended filesystem locations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:26.04:LTS: rsync&lt;/p&gt;
&lt;p&gt;rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver&amp;#39;s destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Attackers can substitute a symlink for a component of the destination path between the path resolution and chdir() call, causing the receiver&amp;#39;s working directory to be established outside the intended destination tree so that subsequent relative-path file writes land in unintended filesystem locations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53796</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2817 — Rsync: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2817</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten offenzulegen oder zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten offenzulegen oder zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2817</guid>
    </item>
  </channel>
</rss>
