SB2026092145 - Anolis OS update for rsync



SB2026092145 - Anolis OS update for rsync

Published: September 21, 2026

Security Bulletin ID SB2026092145
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

High 25% Medium 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper Certificate Validation (CVE-ID: CVE-2026-70454)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and tamper with transmitted data.

The vulnerability exists due to improper certificate validation in the rsync-ssl helper script when establishing TLS connections to an rsync daemon through affected backends. A remote attacker can perform a machine-in-the-middle attack using a certificate that is not properly verified to disclose sensitive information and tamper with transmitted data.

User interaction is required because a user must invoke rsync-ssl.


2) Out-of-bounds write (CVE-ID: CVE-2026-70458)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and modify data.

The vulnerability exists due to out-of-bounds write in the rsync file list handling logic when processing a file entry marked FLAG_HLINKED even though hard links were not negotiated. A remote attacker can send a specially crafted file entry to cause a denial of service and modify data.

Exploitation requires protocol-30 incremental recursion, a regular file entry, and use of --checksum with hard links disabled.


3) Integer overflow (CVE-ID: CVE-2026-70462)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in MSG_IO_TIMEOUT handling when processing a peer-supplied MSG_IO_TIMEOUT message. A remote attacker can send a specially crafted timeout value to cause a denial of service.

User interaction is required because MSG_IO_TIMEOUT is accepted only by the connecting client.


4) Incorrect authorization (CVE-ID: CVE-2026-70463)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to gain unauthorized read or write access.

The vulnerability exists due to incorrect authorization in auth_server() `auth users` parsing when processing `rsyncd.conf` `auth users` values that begin with a comma. A remote user can authenticate as a member of a group that an administrator intended to deny or restrict to read-only to gain unauthorized read or write access.

The issue is silent because the configuration parses without error and a later first-match `:rw` entry can be applied instead of the intended group deny or read-only rule.


Remediation

Install update from vendor's website.