Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95789.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-95789
Upstream
Published
2026-08-13T15:19:52Z
Modified
2026-09-09T06:55:05Z
Summary
CVE-2026-53801 affecting package rsync for versions less than 3.5.0-1
Details

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a path component of the scanned tree can replace a symlink with a directory entry pointing outside the module root between the lstat() call and the subsequent opendir() call, exposing files beyond the intended root in both daemon-mode and non-daemon sender-side scanning.

References

Affected packages

Azure Linux:3 / rsync

Package

Name
rsync
Purl
pkg:rpm/azure-linux/rsync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95789.json"