PT-2026-71639 · Rsync · Rsync

CVE-2026-53801

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description A symlink race condition exists in the sender's directory scanning logic. This occurs when an attacker manipulates symlinks in a path component of the scanned tree, replacing a symlink with a directory entry pointing outside the module root between the lstat() call and the subsequent opendir() call. This allows the sender to enumerate and transfer files outside the intended subtree in both daemon-mode and non-daemon sender-side scanning.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95789
CVE-2026-53801
ECHO-67F1-7AAD-51AF
GHSA-MCH3-QR4P-CHGM
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync