{"id":"AZL-95849","summary":"CVE-2026-53799 affecting package rsync for versions less than 3.5.0-1","details":"rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.","modified":"2026-08-30T05:26:50Z","published":"2026-08-13T15:19:52Z","upstream":["CVE-2026-53799"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53799"}],"affected":[{"package":{"name":"rsync","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95849.json"}}],"schema_version":"1.9.0"}