PT-2026-71638 · Rsync · Rsync

·

CVE-2026-53800

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v4.0

5.7

Medium

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description A symlink race condition exists in the --remove-source-files feature. This occurs when an attacker with symlink creation access atomically substitutes a symlink for a source file between the completion of the transfer and the unlink() function call. This action causes the software to delete the symlink target instead of the intended source file, leading to arbitrary file deletion.
Recommendations Update to version 3.5.0 or later. As a temporary mitigation, avoid using the --remove-source-files feature.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95768
CVE-2026-53800
ECHO-5CFE-83A6-5DEA
GHSA-V3VW-PVPG-CHWH
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync