Opened 6 months ago

Closed 5 months ago

#23154 closed enhancement (fixed)

rsync CVE-2026-41035

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

This has just been issued today.

Affects rsync 3.0.1-3.4.1.

Upstream ticket: ​https://github.com/RsyncProject/rsync/issues/871

I'll attach a patch that fixes it, and monitor the upstream ticket until they come up with a final fix.

It's rated as high: ​https://www.cve.org/CVERecord?id=CVE-2026-41035

Attachments (1)

rsync-3.4.1-CVE-2026-41035.patch​ (585 bytes ) - added by Joe Locash 6 months ago.

Download all attachments as: .zip

Change History (5)

by Joe Locash, 6 months ago

comment:1 by Joe Locash, 6 months ago

Priority: normal → high

comment:2 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at d5704878e8. Leaving open for SA.

comment:4 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-053 issued

Note: See TracTickets for help on using tickets.