PT-2026-61715 · Rsync · Rsync
CVE-2026-44509
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.4.3
Description
rsync is a file-copying tool utilizing a delta-transfer algorithm to synchronize files. A symlink race condition exists in path-based system calls such as
chmod() and chown(), as previous fixes for open() calls did not cover these functions. For rsync daemons configured with use chroot = no, a local attacker can exploit this to modify permissions, ownership, or timestamps of files located outside the exported module.Recommendations
Update to version 3.4.3.
Fix
Time Of Check To Time Of Use
Link Following
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rsync