PT-2026-42053 · Rsync+2 · Rsync+2

·

CVE-2026-43619

·

Published

2026-05-20

·

Updated

2026-08-26

CVSS v4.0

7.2

High

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description A symlink race condition exists in path-based system calls, including chmod(), lchown(), utimes(), rename(), unlink(), mkdir(), symlink(), mknod(), link(), rmdir(), and lstat(). Local attackers with filesystem access can exploit the timing window between path resolution and system call execution by swapping symlinks. This allows the redirection of operations to files outside the exported rsync module, enabling the application of sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files. This issue affects rsync daemons configured with use chroot = no.
Recommendations Update to version 3.4.3 or later. Configure rsync daemons to use use chroot = yes to prevent access outside the module boundary.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86985
CVE-2026-43619
ECHO-2DE0-1B04-BAD9
GHSA-4H9M-W5FF-J735
JLSEC-2026-630
OPENSUSE-SU-2026:10857-1
OPENSUSE-SU-2026:20877-1
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:2038-1
SUSE-SU-2026:21726-1
SUSE-SU-2026:21739-1
SUSE-SU-2026:21980-1
SUSE-SU-2026:22015-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3629-1
USN-8283-1
USN-8349-1
USN-8349-2
USN-8349-3

Affected Products

Linuxmint
Ubuntu
Rsync