PT-2026-71635 · Rsync · Rsync
CVE-2026-53797
·
Published
2026-08-13
·
Updated
2026-08-26
CVSS v4.0
5.7
Medium
| Vector | AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
A symlink race condition exists in the sender's source tree traversal. An attacker capable of manipulating a parent directory of the source tree can redirect file reads to unintended paths. This is achieved by atomically replacing a parent directory component with a symlink pointing outside the source root between the path resolution and file open operations, leading to the disclosure of file contents outside the intended transfer root.
Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Link Following
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync