Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Gentoo GLSA

GLSA 202608-03: rsync: Multiple Vulnerabilities

Multiple vulnerabilities in rsync, including at least one high-severity issue (CVSS up to 7.4) that could lead to privilege escalation, affect versions up to and including 3.4.2. The authoritative NVD data indicates specific version ranges are affected, such as samba rsync versions less than 3.4.3 and versions from 3.0.1 through 3.4.1. The resolution is to upgrade to rsync version 3.4.3, as no workaround is currently available.
Read Full Article →

Multiple vulnerabilities have been found in rsync, the worst of which could result in privilege escalation. Affected packages Package net-misc/rsync on all architectures Affected versions < 3.4.3 Unaffected versions >= 3.4.3 Background rsync is a server and client utility that provides fast incremental file transfers. It is used to efficiently synchronize files between hosts and is used by emerge to fetch Gentoo's Portage tree. Description Multiple vulnerabilities have been discovered in rsync. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All rsync users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.4.3" References CVE-2026-29518 CVE-2026-41035 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 CVE-2026-45232 Release date August 13, 2026 Latest revision August 13, 2026: 1 Severity high Exploitable local and remote Bugzilla entries 972779 975525

Share this article