Time-of-check Time-of-use (TOCTOU) Race Condition in Rsync - CVE-2026-29518

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Rsync - CVE-2026-29518

Published: June 1, 2026


Vulnerability identifier: #VU133144
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29518
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information and overwrite files outside the module.

The vulnerability exists due to a time-of-check time-of-use symlink race condition in daemon mode path handling when processing file operations on parent path components without chroot. A local user can replace a parent directory component with a symlink between the check and open operation to disclose sensitive information and overwrite files outside the module.

Only daemon configurations with use chroot = no for a module are vulnerable.


Affected software

Rsync
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Basesystem Module
openSUSE Leap
Fedora
LANTIME Operating System Firmware (LTOS)
rsync (Ubuntu package)
rsync-debugsource
rsync
rsync-debuginfo
rsync-doc
rsync-daemon
rsync (Red Hat package)
rsync (Debian package)
net-misc/rsync

How to mitigate CVE-2026-29518

Install security update from vendor's website.

Rsync - update to 3.4.3
LANTIME Operating System Firmware (LTOS) - update to 7.10.012
rsync (Ubuntu package) - addressed in versions 3.1.0-2ubuntu0.4+esm3, 3.1.0-2ubuntu0.4+esm4, 3.1.1-3ubuntu1.3+esm5, 3.1.1-3ubuntu1.3+esm6, 3.1.2-2.1ubuntu1.6+esm3, 3.1.2-2.1ubuntu1.6+esm4, 3.1.3-8ubuntu0.9+esm1, 3.1.3-8ubuntu0.9+esm2, 3.2.7-0ubuntu0.22.04.6, 3.2.7-0ubuntu0.22.04.7, 3.2.7-1ubuntu1.4, 3.2.7-1ubuntu1.5, 3.4.1+ds1-7ubuntu0.2, 3.4.1+ds1-7ubuntu0.3, 3.4.1+ds1-5ubuntu1.2, 3.4.1+ds1-5ubuntu1.3
rsync-debugsource - addressed in versions 3.1.3-3.43.1, 3.1.3-3.46.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.21.1, 3.3.0-slfo.1.1_6.1
rsync - addressed in versions 3.1.3-3.43.1, 3.1.3-3.46.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.21.1, 3.3.0-slfo.1.1_6.1
rsync-debuginfo - addressed in versions 3.1.3-3.43.1, 3.1.3-3.46.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.21.1, 3.3.0-slfo.1.1_6.1
rsync-doc - update to 3.1.3-27.0.1
rsync - update to 3.1.3-27.0.1
rsync-daemon - update to 3.1.3-27.0.1
rsync (Red Hat package) - addressed in versions 3.2.5-7.el9_8.2, 3.4.4-1.el10_2
rsync (Debian package) - addressed in versions 3.2.7-1+deb12u5, 3.4.1+ds1-5+deb13u3
net-misc/rsync - update to 3.4.3
rsync - addressed in versions 3.4.3-1.fc43, 3.4.3-1.fc44, 3.4.4-1.fc43

External References

Related Security Bulletins