CVE-2026-43619
published 2026-05-20CVE-2026-43619: Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir…
PriorityP336medium6.3CVSS 3.1
AVLACHPRLUINSUCHIHAN
EPSS
0.14%
3.4th percentile
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | < 3.4.3 | 3.4.3 |
| samba | rsync | <= 3.4.2 | — |
| samba | rsync | — | — |
| ubuntu | rsync | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.2HIGHCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.2HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2026-06-16·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to o
Ubuntu
rsync regression
vendor_ubuntu·2026-06-08·CVSS 4.3
CVE-2025-10158 [MEDIUM] rsync regression
Title: rsync regression
Summary: USN-8349-1 introduced regressions in rsync.
USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.
Original advisory details:
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or esc
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 4.3
CVE-2026-43618 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possi
Red Hat
rsync: rsync: Symlink race vulnerability allows unauthorized file operations
vendor_redhat·2026-05-20·CVSS 7.2
CVE-2026-43619 [HIGH] CWE-59 rsync: rsync: Symlink race vulnerability allows unauthorized file operations
rsync: rsync: Symlink race vulnerability allows unauthorized file operations
A flaw was found in rsync. A local attacker with filesystem access on the daemon host can exploit a symlink race vulnerability (CWE-367 Time-of-check to time-of-use) in rsync daemons configured with 'use chroot = no'. This allows the attacker to redirect path-based system calls, such as chmod, lchown, or unlink, outside the intended module. This could lead to unauthorized file operations or other security bypasses.
Statement: Moderate: A symlink race vulnerability affects rsync daemons when configured with `use chroot = no`, allowing a local attacker with filesystem access to perform unauthorized file operations outside the intended module. This risk is present only when the non-default `use chroot = no` setting
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2026-05-20·CVSS 4.3
CVE-2026-43620 [MEDIUM] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly val
VulDB
RsyncProject rsync up to 3.4.2 Exported Rsync toctou (GHSA-4h9m-w5ff-j735 / Nessus ID 315780)
vuldb·2026-06-02·CVSS 7.2
CVE-2026-43619 [HIGH] RsyncProject rsync up to 3.4.2 Exported Rsync toctou (GHSA-4h9m-w5ff-j735 / Nessus ID 315780)
A vulnerability was found in RsyncProject rsync up to 3.4.2. It has been classified as problematic. This affects an unknown part of the component Exported Rsync Module. The manipulation leads to time-of-check time-of-use.
This vulnerability is uniquely identified as CVE-2026-43619. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-pwrq-5rj3-c43m: Rsync version 3
ghsa_unreviewed·2026-05-20
CVE-2026-43619 [HIGH] CWE-59 GHSA-pwrq-5rj3-c43m: Rsync version 3
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.
No detection rules found.
No public exploits indexed.
2026-05-20
Published