Bug 2531539 (CVE-2026-88016)

Summary: CVE-2026-88016 rclone: rclone: Directory metadata escape via planted symlink allows unauthorized file modification
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in rclone. When the backend/local component operates with the --links option, a specially crafted .rclonelink object from the source can create a symbolic link (symlink) in the destination. Subsequently, directory metadata operations, such as changing ownership, permissions, or modification times, are applied through this planted symlink. This allows an attacker controlling the source contents to modify the ownership, permissions, or timestamps of files or directories outside the intended destination, potentially leading to unauthorized data modification or privilege escalation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2536986, 2536987    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-10 16:07:32 UTC
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.