PT-2022-4620 · Rsync+11 · Rsync+11

Ege Balci

+1

·

Published

2022-08-02

·

Updated

2025-09-29

·

CVE-2022-29154

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.2.5
Description An issue in rsync allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories, for example, overwrite the .ssh/authorized keys file.
Recommendations For versions prior to 3.2.5, update to version 3.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the rsync client target directory and subdirectories to minimize the risk of exploitation. Avoid using the rsync client with untrusted servers until the issue is resolved.

Exploit

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6180
ALSA-2022_6180
ALSA-2022_7106
ALSA-2022_7314
ALSA-2022_7793
ALSA-2022_8291
ALSA-2025_16880
ALT-PU-2022-2327
ALT-PU-2022-2368
ALT-PU-2022-2434
AZL-10461
BDU:2022-05498
CESA-2022_6170
CESA-2022_6180
CVE-2022-29154
ELSA-2022-6170
ELSA-2022-6180
ELSA-2022-6181
MGASA-2022-0302
OESA-2022-1875
OPENSUSE-SU-2022_2825-1
OPENSUSE-SU-2022_2959-1
OPENSUSE-SU-2024:12232-1
RHSA-2022:6170
RHSA-2022:6171
RHSA-2022:6172
RHSA-2022:6173
RHSA-2022:6180
RHSA-2022:6181
RHSA-2022:6551
RHSA-2022_6170
RHSA-2022_6180
RHSA-2022_6181
RLSA-2022:6180
RLSA-2022:6181
RLSA-2022_6180
RLSA-2022_6181
SUSE-RU-2023:3370-1
SUSE-SU-2022:2825-1
SUSE-SU-2022:2858-1
SUSE-SU-2022:2859-1
SUSE-SU-2022:2959-1
SUSE-SU-2022:2959-2
SUSE-SU-2022_2825-1
SUSE-SU-2022_2858-1
SUSE-SU-2022_2859-1
SUSE-SU-2022_2959-1
SUSE-SU-2026:21726-1
USN-5921-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Rsync