PT-2026-71637 · Rsync · Rsync
CVSS v4.0
7.2
High
| Vector | AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
A symlink race condition exists where a local attacker can cause the software to apply arbitrary Access Control Lists (ACLs) or extended attributes to unintended files. This occurs when a symlink is substituted at a predictable destination path between the file write operation and the subsequent
acl set file() or lsetxattr() function calls. By exploiting this timing window, an attacker can redirect the application of ACLs and extended attributes to files outside the intended destination tree, which may lead to elevated permissions and local privilege escalation.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
LPE
Link Following
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync