{"id":"CLSA-2026-1776769741","summary":"rsync: Fix of 3 CVEs","details":"- CVE-2017-16548: fix heap overread in receive_xattr by enforcing trailing\n  NUL on received xattr names\n- CVE-2017-17434: sanitize xname in read_ndx_and_attrs and check daemon\n  filter against fnamecmp in recv_files\n- CVE-2018-5764: prevent client from resetting protect_args during the\n  second parse_arguments pass on the daemon","modified":"2026-06-01T00:32:20.332143403Z","published":"2026-04-21T11:09:06Z","upstream":["CVE-2017-16548","CVE-2017-17434","CVE-2018-5764"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/oraclelinux6els/CLSA-2026-1776769741.html"}],"affected":[{"package":{"name":"rsync","ecosystem":"TuxCare:OracleLinux:6","purl":"pkg:rpm/tuxcare/rsync?distro=oraclelinux-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.6-12.el6.tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux6els/CLSA-2026-1776769741.json"}}],"schema_version":"1.7.5"}