Opened 6 months ago
Closed 5 months ago
#23154 closed enhancement (fixed)
rsync CVE-2026-41035
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
This has just been issued today.
Affects rsync 3.0.1-3.4.1.
Upstream ticket: https://github.com/RsyncProject/rsync/issues/871
I'll attach a patch that fixes it, and monitor the upstream ticket until they come up with a final fix.
It's rated as high: https://www.cve.org/CVERecord?id=CVE-2026-41035
Attachments (1)
Change History (5)
by , 6 months ago
| Attachment: | rsync-3.4.1-CVE-2026-41035.patch added |
|---|
comment:1 by , 6 months ago
| Priority: | normal → high |
|---|
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Note:
See TracTickets
for help on using tickets.

Fixed at d5704878e8. Leaving open for SA.