SB2026092145 - Anolis OS update for rsync
Published: September 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Improper Certificate Validation (CVE-ID: CVE-2026-70454)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and tamper with transmitted data.
The vulnerability exists due to improper certificate validation in the rsync-ssl helper script when establishing TLS connections to an rsync daemon through affected backends. A remote attacker can perform a machine-in-the-middle attack using a certificate that is not properly verified to disclose sensitive information and tamper with transmitted data.
User interaction is required because a user must invoke rsync-ssl.
2) Out-of-bounds write (CVE-ID: CVE-2026-70458)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and modify data.
The vulnerability exists due to out-of-bounds write in the rsync file list handling logic when processing a file entry marked FLAG_HLINKED even though hard links were not negotiated. A remote attacker can send a specially crafted file entry to cause a denial of service and modify data.
Exploitation requires protocol-30 incremental recursion, a regular file entry, and use of --checksum with hard links disabled.
3) Integer overflow (CVE-ID: CVE-2026-70462)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in MSG_IO_TIMEOUT handling when processing a peer-supplied MSG_IO_TIMEOUT message. A remote attacker can send a specially crafted timeout value to cause a denial of service.
User interaction is required because MSG_IO_TIMEOUT is accepted only by the connecting client.
4) Incorrect authorization (CVE-ID: CVE-2026-70463)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain unauthorized read or write access.
The vulnerability exists due to incorrect authorization in auth_server() `auth users` parsing when processing `rsyncd.conf` `auth users` values that begin with a comma. A remote user can authenticate as a member of a group that an administrator intended to deny or restrict to read-only to gain unauthorized read or write access.
The issue is silent because the configuration parses without error and a later first-match `:rw` entry can be applied instead of the intended group deny or read-only rule.
Remediation
Install update from vendor's website.