GHSA-ffg2-fr5g-3rxw on CTRL-OS 26.05
Aliases: GHSA-ffg2-fr5g-3rxw, CVE-2026-53784
Packages: rsync
Status: Plausible
Advisory Information
With
use chroot = nothe daemon changes directory into the module path using a plainchdir()that followed an attacker-planted parent-component symlink, causing the daemon to serve files from outside the configured module before any transfer began.Fix: confine the module-root chdir through the secure resolver.
Test: daemon-module-chdir-symlink.
Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)
Updates
2026-08-14 16:57 CEST
Metadata changes:
- Status for package
rsync: “Plausible”
2026-08-14 16:55 CEST
Metadata changes:
- Status for package
rsync: “New”