rsync-3.2.5-7.el9_8.2
エラータID: AXSA:2026-1343:07
リリース日:
2026/07/27 Monday - 17:43
題名:
rsync-3.2.5-7.el9_8.2
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- rsync には、競合状態に至る問題があるため、ローカルの攻撃者
により、特権昇格を可能とする脆弱性が存在します。(CVE-2026-29518)
- rsync には、整数オーバーフローの問題があるため、リモートの
攻撃者により、情報の漏洩、データ破壊、およびサービス拒否攻撃を
可能とする脆弱性が存在します。(CVE-2026-43618)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
CVE-2026-43618
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
追加情報:
N/A
ダウンロード:
SRPMS
- rsync-3.2.5-7.el9_8.2.src.rpm
MD5: 738cfbea94b0f26ac4bc90732321e0b7
SHA-256: a929f2f3c4ed845e200fd0b246dff2f6a78537a41e9c026243660d040a1e705f
Size: 1.29 MB
Asianux Server 9 for x86_64
- rsync-3.2.5-7.el9_8.2.x86_64.rpm
MD5: 0a5e6ad954687eb8e4eded180d819489
SHA-256: d8dc26a033a0fc2db482b0cc21b2a4e22385750458e19f73d73eebbb3dc18e51
Size: 417.04 kB - rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm
MD5: e93cde3020be3354642b8aaa2036cd59
SHA-256: e3054155b54ba829e67b92e218b4d80684985deb75fd1944c12879fd85fbb06f
Size: 9.49 kB - rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm
MD5: 3c6211ec59f28d8ca6054f2f72b9dfeb
SHA-256: babda99ff98041bae59f2b8aad0f589fb31091835093a164b1da6d8bb5ec0f48
Size: 14.64 kB