SB20260921115 - Red Hat Enterprise Linux 10 update for rsync



SB20260921115 - Red Hat Enterprise Linux 10 update for rsync

Published: September 21, 2026

Security Bulletin ID SB20260921115
CSH Severity
High
Patch available
YES
Number of vulnerabilities 21
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 33% Medium 48% Low 19%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 21 vulnerabilities.


1) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-53791)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass host-based access control and spoof the daemon's source address.

The vulnerability exists due to authentication bypass by spoofing in PROXY-protocol mode when handling a direct client connection with a supplied PROXY header. A remote attacker can send a forged PROXY header to bypass host-based access control and spoof the daemon's source address.

The issue occurs when proxy protocol = true is enabled and the client connects directly rather than through a trusted proxy.


2) Link following (CVE-ID: CVE-2026-53783)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify files outside the restricted directory.

The vulnerability exists due to improper link resolution before file access and unsafe option allowlisting in the rrsync SSH forced-command wrapper when handling rsync arguments and options in a restricted directory. A remote user can replace a validated path component with a symlink or use dangerous allowed options to disclose sensitive information and modify files outside the restricted directory.

The issue affects restricted non-root directory configurations and does not require user interaction.


3) Link following (CVE-ID: CVE-2026-53785)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to create files and directories outside the destination tree.

The vulnerability exists due to improper link resolution before file access in make_path() when re-creating implied parent directories under --relative transfers. A local user can plant a symlink in a parent path component to create files and directories outside the destination tree.

The issue occurs on the receiver side while handling transferred paths with implied parent directories.


4) UNIX symbolic link following (CVE-ID: CVE-2026-53802)

CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and manipulate file transfer behavior.

The vulnerability exists due to improper link resolution before file access in operator-supplied input file handling when processing paths for filter merge files, files-from lists, include-from and exclude-from lists, password files, secrets files, and daemon files-from inputs. A local user can plant a symlink in a controlled path component to disclose sensitive information and manipulate file transfer behavior.

In the password-file and secrets-file cases, file contents may be sent as the daemon authentication response. The daemon files-from variant can read a file outside the served module.


5) Out-of-bounds write (CVE-ID: CVE-2026-70461)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in add_implied_include() when processing transfer arguments sent by a peer. A remote attacker can send a specially crafted files-from entry to cause a denial of service.

The issue is reachable on a standard network rsync daemon with a read-only module, and no crafted protocol is required.


6) Out-of-bounds write (CVE-ID: CVE-2026-70457)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and modify memory.

The vulnerability exists due to an out-of-bounds write in parse_size_arg() when processing oversized size-related option values forwarded through server_options(). A remote attacker can send specially crafted --max-size, --min-size, --max-alloc, --bwlimit, or --block-size values to cause a denial of service and modify memory.

The issue results in a fixed two-byte write of newline and NUL at an attacker-chosen offset in .bss.


7) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-70455)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the rsync daemon sender when processing a PULL request with a large --compress-threads value. A remote attacker can send a request that names a large worker count to cause a denial of service.

A stock client is sufficient, and no crafted protocol is required. On anonymous modules, no authentication is required.


8) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-70453)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in hash_search() when processing a crafted checksum set containing a long chain of equal weak checksums. A remote attacker can send a specially crafted checksum set to cause a denial of service.

Sustained CPU consumption can persist as shared host resource exhaustion rather than being limited to the attacker's own transfer.


9) Link following (CVE-ID: CVE-2026-53793)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and modify files outside the intended inner module.

The vulnerability exists due to improper link resolution before file access in rsync inner-module path handling when processing a chrooted "/./" inner module with a parent-component symlink or a peer-forged delta-basis path. A remote attacker can supply crafted path components to access files outside the inner module to disclose sensitive information and modify files outside the intended inner module.

The issue occurs when use chroot = yes is enabled with a "/./" inner module, and it also affects peer-controlled delta-basis names during client pull operations with --link-dest, --copy-dest, --compare-dest, or --fuzzy.


10) Out-of-bounds write (CVE-ID: CVE-2026-70456)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or modify memory.

The vulnerability exists due to out-of-bounds write in read_args() when processing daemon client arguments that make glob expansion land the argument count exactly on maxargs. A remote attacker can send a specially crafted request to cause a denial of service or modify memory.

The write occurs when a trailing NULL pointer is written one pointer past the end of the heap allocation.


11) Link following (CVE-ID: CVE-2026-53795)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to overwrite files outside the destination tree.

The vulnerability exists due to improper link resolution before file access in do_rename_at()/do_link_at() when handling transfers that use an absolute --temp-dir, an absolute --link-dest basis, or mixed-parent rename/link paths. A remote attacker can flip a destination parent component from a directory to a symlink mid-transfer to overwrite files outside the destination tree.

User interaction is required to initiate the transfer.


12) Link following (CVE-ID: CVE-2026-70460)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read files or overwrite, rename, or unlink files outside the module root.

The vulnerability exists due to improper link resolution before file access in the rsync daemon module path resolver when processing peer-supplied --partial-dir or --backup-dir values that resolve through an in-module symlink. A remote attacker can supply a crafted directory value to read files or overwrite, rename, or unlink files outside the module root.

Exploitation requires a trusted in-module symlink owned by uid 0 or the daemon effective uid to already exist along the resolved path, and reach is limited to locations accessible through that symlink by the daemon effective uid.


13) Not Failing Securely ('Failing Open') (CVE-ID: CVE-2026-70452)

CWE-ID: CWE-636 - Not Failing Securely (\'Failing Open\')

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass host-based access restrictions and gain unauthorized access.

The vulnerability exists due to not failing securely in hosts deny access control processing when performing a forward DNS lookup of a configured hostname token. A remote attacker can connect from a host that should be denied to bypass host-based access restrictions and gain unauthorized access.

The issue occurs when forward lookup is enabled and a hostname token in hosts deny cannot be resolved, including during transient resolver failures or when a global daemon chroot lacks resolver configuration.


14) Incorrect authorization (CVE-ID: CVE-2026-70463)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to gain unauthorized read or write access.

The vulnerability exists due to incorrect authorization in auth_server() `auth users` parsing when processing `rsyncd.conf` `auth users` values that begin with a comma. A remote user can authenticate as a member of a group that an administrator intended to deny or restrict to read-only to gain unauthorized read or write access.

The issue is silent because the configuration parses without error and a later first-match `:rw` entry can be applied instead of the intended group deny or read-only rule.


15) Link following (CVE-ID: CVE-2026-53784)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information and modify served content outside the configured module root.

The vulnerability exists due to improper link resolution before file access in the daemon module-root chdir logic when changing directory into the module path with use chroot = no. A local user can place a parent-component symlink to make the daemon serve files from outside the configured module root to disclose sensitive information and modify served content outside the configured module root.

Exploitation requires the daemon to be configured with use chroot = no, and the issue occurs before any transfer begins.


16) Link following (CVE-ID: CVE-2026-53803)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to overwrite arbitrary files and escalate privileges.

The vulnerability exists due to improper link resolution before file access in rsync output and ancillary file path handling when opening operator-supplied paths such as --log-file, --write-batch, --read-batch, and daemon ancillary files. A local user can plant a symlink in the target path or a parent path component to overwrite arbitrary files and escalate privileges.

For --read-batch, a planted symlink, FIFO, or device can supply chosen bytes to the protocol parser.


17) Resource exhaustion (CVE-ID: CVE-2026-70464)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the rsync daemon handshake handling when processing pre-transfer handshake input. A remote attacker can stall the connection by sending an unterminated line or trickling NUL-terminated arguments one byte at a time to cause a denial of service.

A stall after module selection can hold a max-connections slot and make the module unavailable to legitimate clients.


18) Out-of-bounds write (CVE-ID: CVE-2026-70458)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and modify data.

The vulnerability exists due to out-of-bounds write in the rsync file list handling logic when processing a file entry marked FLAG_HLINKED even though hard links were not negotiated. A remote attacker can send a specially crafted file entry to cause a denial of service and modify data.

Exploitation requires protocol-30 incremental recursion, a regular file entry, and use of --checksum with hard links disabled.


19) OS Command Injection (CVE-ID: CVE-2026-53790)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to improper neutralization of special elements in shell commands and command arguments in rsync command construction and helper invocation when processing peer- or host-controlled values. A remote attacker can supply specially crafted host, environment, hostspec, or remote path values to execute arbitrary commands.

The issue affects multiple injection sinks, including RSYNC_CONNECT_PROG host substitution, daemon exec hook expansion, rsync-ssl helper invocation, and remote-shell argument quoting for newline or carriage return characters.


20) Input validation error (CVE-ID: CVE-2026-53789)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the rsync receiver file-list handling when processing file-list entries from a malicious sender under --delete or --force. A remote attacker can send crafted transfer-root or implied-parent entries to cause a denial of service.

User interaction is required to initiate a transfer from a malicious sender.


21) Improper Certificate Validation (CVE-ID: CVE-2026-70454)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and tamper with transmitted data.

The vulnerability exists due to improper certificate validation in the rsync-ssl helper script when establishing TLS connections to an rsync daemon through affected backends. A remote attacker can perform a machine-in-the-middle attack using a certificate that is not properly verified to disclose sensitive information and tamper with transmitted data.

User interaction is required because a user must invoke rsync-ssl.


Remediation

Install update from vendor's website.