{"id":"AZL-95804","summary":"CVE-2026-53798 affecting package rsync for versions less than 3.5.0-1","details":"rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.","modified":"2026-08-31T05:26:27Z","published":"2026-08-13T15:19:51Z","upstream":["CVE-2026-53798"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53798"}],"affected":[{"package":{"name":"rsync","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95804.json"}}],"schema_version":"1.9.0"}