PT-2026-71636 · Rsync · Rsync
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
A privilege confusion issue exists in the name-converter subprocess uid/gid mapping. Local attackers can cause transferred files to be owned by root by influencing the name-converter responses to return empty values. When the subprocess returns an empty response for a uid or gid lookup, the software incorrectly interprets this as a successful resolution to uid/gid 0 (root) instead of a lookup failure. If the name-converter also signals fake super-user status, root ownership is assigned to the transferred files.
Recommendations
Update to version 3.5.0 or later.
Exploit
Fix
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync