rsync-3.2.5-7.el9_8.2

エラータID: AXSA:2026-1343:07

Release date: 
Monday, July 27, 2026 - 17:43
Subject: 
rsync-3.2.5-7.el9_8.2
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

* rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding (CVE-2026-43618)
* rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. (CVE-2026-29518)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-43618
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rsync-3.2.5-7.el9_8.2.src.rpm
    MD5: 738cfbea94b0f26ac4bc90732321e0b7
    SHA-256: a929f2f3c4ed845e200fd0b246dff2f6a78537a41e9c026243660d040a1e705f
    Size: 1.29 MB

Asianux Server 9 for x86_64
  1. rsync-3.2.5-7.el9_8.2.x86_64.rpm
    MD5: 0a5e6ad954687eb8e4eded180d819489
    SHA-256: d8dc26a033a0fc2db482b0cc21b2a4e22385750458e19f73d73eebbb3dc18e51
    Size: 417.04 kB
  2. rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm
    MD5: e93cde3020be3354642b8aaa2036cd59
    SHA-256: e3054155b54ba829e67b92e218b4d80684985deb75fd1944c12879fd85fbb06f
    Size: 9.49 kB
  3. rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm
    MD5: 3c6211ec59f28d8ca6054f2f72b9dfeb
    SHA-256: babda99ff98041bae59f2b8aad0f589fb31091835093a164b1da6d8bb5ec0f48
    Size: 14.64 kB