Link following in Rsync - CVE-2026-53797
Published: August 13, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper link resolution before file access in the sender file-content opening logic when processing transferred files by path after the file-list scan. A local user can race a parent directory from a real directory to a symlink pointing outside the source tree to disclose sensitive information.
This issue affects local or non-daemon sender operation and requires winning a race condition after the file-list scan.