DEBIAN-CVE-2026-53801

Source
https://security-tracker.debian.org/tracker/CVE-2026-53801
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53801.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-53801
Upstream
Published
2026-08-13T15:19:52Z
Modified
2026-09-01T16:06:50Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender to enumerate and transfer files outside the module root's intended subtree. Attackers who can create or manipulate symlinks in a path component of the scanned tree can replace a symlink with a directory entry pointing outside the module root between the lstat() call and the subsequent opendir() call, exposing files beyond the intended root in both daemon-mode and non-daemon sender-side scanning.

References

Affected packages

Debian:12 / rsync

Package

Name
rsync
Purl
pkg:deb/debian/rsync?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.2.7-1
3.2.7-1+deb12u1
3.2.7-1+deb12u2
3.2.7-1+deb12u3
3.2.7-1+deb12u4
3.2.7-1+deb12u5
3.2.7-1+deb12u6
3.3.0-1
3.3.0+ds1-1
3.3.0+ds1-2
3.3.0+ds1-3
3.3.0+ds1-4
3.4.1+ds1-1
3.4.1+ds1-2
3.4.1+ds1-3
3.4.1+ds1-4~exp1
3.4.1+ds1-4~exp2
3.4.1+ds1-4
3.4.1+ds1-5~exp1
3.4.1+ds1-5
3.4.1+ds1-6
3.4.1+ds1-7
3.4.1+ds1-8~exp1
3.4.2+ds1-1
3.4.2+ds1-2
3.4.3+ds1-1
3.4.3+ds1-2
3.4.4+ds1-1
3.5.0+ds1-1
3.5.0+ds1-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53801.json"

Debian:13 / rsync

Package

Name
rsync
Purl
pkg:deb/debian/rsync?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.1+ds1-5
3.4.1+ds1-5+deb13u1
3.4.1+ds1-5+deb13u2
3.4.1+ds1-5+deb13u3
3.4.1+ds1-5+deb13u4
3.4.1+ds1-6
3.4.1+ds1-7
3.4.1+ds1-8~exp1
3.4.2+ds1-1
3.4.2+ds1-2
3.4.3+ds1-1
3.4.3+ds1-2
3.4.4+ds1-1
3.5.0+ds1-1
3.5.0+ds1-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53801.json"

Debian:14 / rsync

Package

Name
rsync
Purl
pkg:deb/debian/rsync?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.0+ds1-1

Affected versions

3.*
3.4.1+ds1-5
3.4.1+ds1-6
3.4.1+ds1-7
3.4.1+ds1-8~exp1
3.4.2+ds1-1
3.4.2+ds1-2
3.4.3+ds1-1
3.4.3+ds1-2
3.4.4+ds1-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-53801.json"