gpp_maybe
Security update for rsync
SUSE-SLE-Micro-6.0-720
This update for rsync fixes the following issues Security issues: - CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511). - CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515). - CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512). - CVE-2026-43619: Symlink Race Condition via Path-Based Syscalls (bsc#1264514). - CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513). - CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296). Non security issues: - rsync --delay-updates never updates after interruption (bsc#1204538). - Fix duplication of flag causing illegal hashkey failures.
-
Release DateMay 21 2026
-
ReferencesBugzilla: 1201840, 1202970, 1204538, 1234100, 1234101, 1234102, 1234103, 1234104, 1235475, 1254441, 1262223, 1264511, 1264512, 1264513, 1264514, 1264515, 1265296
CVEs: CVE-2022-29154, CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747, CVE-2025-10158, CVE-2026-29518, CVE-2026-41035, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.0 aarch64
-
Packages
SUSE Linux Micro 6.0 s390x
-
Packages
SUSE Linux Micro 6.0 x86_64
-
Packages