Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in rsync. An rsync daemon configured with "use chroot = no" is exposed to a time-of-check / time-of-use race on parent path components. A local attacker with write access to a module can replace a parent directory component with a symlink between the receiver's check and its open(), redirecting reads (basis-file disclosure) and writes (file overwrite) outside the module. Under elevated daemon privilege this allows privilege escalation. Default "use chroot = yes" is not exposed.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:26332 https://access.redhat.com/errata/RHSA-2026:26332
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:26410 https://access.redhat.com/errata/RHSA-2026:26410
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:26408 https://access.redhat.com/errata/RHSA-2026:26408