Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in rsync. A local attacker with filesystem access on the daemon host can exploit a symlink race vulnerability (CWE-367 Time-of-check to time-of-use) in rsync daemons configured with 'use chroot = no'. This allows the attacker to redirect path-based system calls, such as chmod, lchown, or unlink, outside the intended module. This could lead to unauthorized file operations or other security bypasses.