Skip to content

GHSA-ffg2-fr5g-3rxw

CVE Information

With use chroot = no the daemon changes directory into the module path using a plain chdir() that followed an attacker-planted parent-component symlink, causing the daemon to serve files from outside the configured module before any transfer began.

Fix: confine the module-root chdir through the secure resolver.

Test: daemon-module-chdir-symlink.

Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)