Bug 2469055 (CVE-2026-29518) - CVE-2026-29518 rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.
Summary: CVE-2026-29518 rsync: TOCTOU symlink race condition allowing local privilege ...
Keywords:
Status: NEW
Alias: CVE-2026-29518
Deadline: 2026-05-20
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-11 13:53 UTC by OSIDB Bzimport
Modified: 2026-05-22 13:10 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-11 13:53:35 UTC
A flaw was found in rsync. An rsync daemon configured with "use chroot = no" is exposed
to a time-of-check / time-of-use race on parent path components. A local
attacker with write access to a module can replace a parent directory
component with a symlink between the receiver's check and its open(),
redirecting reads (basis-file disclosure) and writes (file overwrite)
outside the module. Under elevated daemon privilege this allows privilege
escalation. Default "use chroot = yes" is not exposed.


Note You need to log in before you can comment on or make changes to this bug.