gpp_maybe Security update for rsync
SUSE-SLE-Module-Basesystem-15-SP7-2026-3657


This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot "/./" inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429).


cloud_download Downloads

Basesystem Module 15.7 aarch64
  • Packages
    rsync
    Versatile tool for fast incremental file transfer
    3.2.7-150600.3.24.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
  • Packages
    rsync
    Versatile tool for fast incremental file transfer
    3.2.7-150600.3.24.1 lock rpm lock src
Basesystem Module 15.7 s390x
  • Packages
    rsync
    Versatile tool for fast incremental file transfer
    3.2.7-150600.3.24.1 lock rpm lock src
Basesystem Module 15.7 x86_64
  • Packages
    rsync
    Versatile tool for fast incremental file transfer
    3.2.7-150600.3.24.1 lock rpm lock src