PT-2026-61715 · Rsync · Rsync

CVE-2026-44509

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.4.3
Description rsync is a file-copying tool utilizing a delta-transfer algorithm to synchronize files. A symlink race condition exists in path-based system calls such as chmod() and chown(), as previous fixes for open() calls did not cover these functions. For rsync daemons configured with use chroot = no, a local attacker can exploit this to modify permissions, ownership, or timestamps of files located outside the exported module.
Recommendations Update to version 3.4.3.

Fix

Time Of Check To Time Of Use

Link Following

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44509

Affected Products

Rsync