{"id":"RHSA-2026:67463","summary":"Red Hat Security Advisory: rsync security, bug fix, and enhancement update","modified":"2026-09-15T10:32:31.536763003Z","published":"2026-09-15T10:17:15Z","upstream":["CVE-2026-53783","CVE-2026-53784","CVE-2026-53785","CVE-2026-53789","CVE-2026-53790","CVE-2026-53791","CVE-2026-53793","CVE-2026-53795","CVE-2026-53802","CVE-2026-53803","CVE-2026-70452","CVE-2026-70453","CVE-2026-70454","CVE-2026-70455","CVE-2026-70456","CVE-2026-70457","CVE-2026-70458","CVE-2026-70460","CVE-2026-70461","CVE-2026-70463","CVE-2026-70464"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67463"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515368"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515373"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515378"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515379"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515380"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515381"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515384"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515385"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515386"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515387"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515389"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515395"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515396"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515403"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515406"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515409"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515417"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515419"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67463.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53783"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53783"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53783"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53784"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53784"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53784"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-ffg2-fr5g-3rxw"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-path-traversal-via-symlink-module-root"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53785"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53785"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53785"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-pph3-7xmf-rrqg"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-path-traversal-write-escape-via-relative-mode"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53789"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515375"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53789"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53789"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-fxwg-7hmf-xh5q"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-arbitrary-file-deletion-via-malicious-file-list"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53790"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53790"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53790"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-5hcf-7xxm-rmqq"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-command-injection-via-multiple-code-paths"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53791"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53791"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53791"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-h2q9-5fr8-w635"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-daemon-ip-spoofing-via-proxy-protocol-header"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53793"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53793"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53793"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-wj7w-vh23-mm44"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-path-confinement-bypass-via-boundary-marker-in-chroot-mode"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53795"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53795"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53795"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-m9vj-637x-v6pq"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-arbitrary-file-write-via-temp-dir-link-dest"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53802"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515416"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53802"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53802"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-53803"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-53803"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53803"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-g9f4-7q66-9582"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-symlink-following-arbitrary-file-overwrite"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70452"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70452"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70452"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-6692-28cx-wpqq"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-access-control-bypass-via-dns-resolution-failure"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70453"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70453"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70453"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-8x5r-mjx8-83hv"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-algorithmic-complexity-dos-via-hash-search"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70454"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70454"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70454"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-3c3x-ww2w-5r5p"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-tls-certificate-validation-bypass-via-ssl-openssl-mode"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70455"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70455"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70455"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-rjvj-qgqg-cvx9"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-dos-via-zt-zstandard-compression-thread-exhaustion"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70456"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70456"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70456"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-78jc-79jv-v6rw"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-read-args"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70457"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515407"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70457"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70457"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-pg7g-xqmr-xpfh"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-parse-size-arg"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70458"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70458"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70458"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-gg3m-4m9m-268h"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-flag-hlinked-handling"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70460"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70460"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70460"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-w3xf-j2r2-gv4x"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-path-traversal-via-partial-dir-backup-dir-symlink"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70461"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70461"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70461"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-jhxm-j4mq-3fj4"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-files-from-entry"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70463"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70463"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70463"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-pfj8-79vq-xgvr"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-authorization-bypass-via-auth-users-directive-parsing"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-70464"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-70464"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70464"},{"type":"ARTICLE","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-hrwq-ccf7-rw5m"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/rsync-connection-slot-exhaustion-dos-via-handshake-stall"}],"affected":[{"package":{"name":"rsync-daemon","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rsync-daemon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.0-3.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"}},{"package":{"name":"rsync-rrsync","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rsync-rrsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.0-3.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"}},{"package":{"name":"rsync","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.0-3.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"}},{"package":{"name":"rsync-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rsync-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.0-3.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"}},{"package":{"name":"rsync-debugsource","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rsync-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.5.0-3.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67463.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}