Skip to content

GHSA-ffg2-fr5g-3rxw on CTRL-OS 26.05

Aliases: GHSA-ffg2-fr5g-3rxw, CVE-2026-53784

Packages: rsync

Status: Plausible

Advisory Information

With use chroot = no the daemon changes directory into the module path using a plain chdir() that followed an attacker-planted parent-component symlink, causing the daemon to serve files from outside the configured module before any transfer began.

Fix: confine the module-root chdir through the secure resolver.

Test: daemon-module-chdir-symlink.

Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)

Updates

2026-08-14 16:57 CEST

Metadata changes:

  • Status for package rsync: “Plausible

2026-08-14 16:55 CEST

Metadata changes:

  • Status for package rsync: “New