PT-2026-71641 · Rsync · Rsync

·

CVE-2026-53803

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description A symlink following issue exists where local attackers can overwrite arbitrary files by placing a symbolic link at a predictable output path. This occurs because the software fails to reject symlinks during ancillary file writes, allowing output to be redirected to arbitrary filesystem locations. This can lead to local privilege escalation on installations where the software runs with elevated privileges, such as setuid or privileged daemon configurations. Affected output paths include --log-file, --write-batch, and daemon-mode log and statistics paths.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95771
CVE-2026-53803
ECHO-4F46-4DDD-9DFD
GHSA-G9F4-7Q66-9582
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync