Bug 2515375 (CVE-2026-53789) - CVE-2026-53789 rsync: rsync: Arbitrary file deletion via malicious file list
Summary: CVE-2026-53789 rsync: rsync: Arbitrary file deletion via malicious file list
Keywords:
Status: NEW
Alias: CVE-2026-53789
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2528651 2528653
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 15:50 UTC by OSIDB Bzimport
Modified: 2026-09-04 16:35 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-13 15:50:57 UTC
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.


Note You need to log in before you can comment on or make changes to this bug.