[Git][security-tracker-team/security-tracker][master] Track fixed version via unstable for rsync issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 17 05:29:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8766c6d2 by Salvatore Bonaccorso at 2026-08-17T06:28:36+02:00
Track fixed version via unstable for rsync issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7118,103 +7118,103 @@ CVE-2025-9486 (GitLab has remediated an issue in GitLab EE affecting all version
CVE-2024-27253 (IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an auth ...)
NOT-FOR-US: IBM
CVE-2026-53802 (rsync before 3.5.0 contains an arbitrary file read vulnerability that ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53803 (rsync before 3.5.0 contains a symlink following vulnerability that all ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53785 (rsyncbefore 3.5.0contains a path traversal vulnerability that allows a ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53784 (rsync before 3.5.0contains a path traversal vulnerability that allows ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53793 (rsync before 3.5.0contains a path confinement bypass vulnerability tha ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53795 (rsync before 3.5.0contains an arbitrary file write vulnerability that ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53796 (rsync before 3.5.0contains a time-of-check to time-of-use (TOCTOU) rac ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53797 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53799 (rsync before 3.5.0contains a symlink race condition vulnerability that ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53800 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53801 (rsync before 3.5.0contains a symlink race condition vulnerability in t ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53783 (rsync before3.5.0 contains a time-of-check to time-of-use (TOCTOU) rac ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53786 (rsyncbefore 3.5.0contains a filter rule bypass vulnerability that allo ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53798 (rsync before 3.5.0contains a privilege confusion vulnerability in the ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53788 (rsync before 3.5.0contains a newline injection vulnerability in the na ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53789 (rsync before 3.5.0contains an improper path handling vulnerability tha ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53791 (rsync daemon before 3.5.0contains an IP address spoofing vulnerability ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53790 (rsync before 3.5.0contains multiple command and argument injection vul ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53792 (rsyncbefore 3.5.0contains an out-of-bounds read vulnerability in the s ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53794 (rsync before 3.5.0contains a logic error in --max-alloc handling that ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70461 (rsync 3.2.5 before 3.5.0contains a heap out-of-bounds write vulnerabil ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70458 (rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70456 (rsync 3.0.1 before 3.5.0contains an out-of-bounds write vulnerability ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70457 (rsync 3.2.3before 3.5.0contains an out-of-bounds write in parse_size_a ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70459 (rsync 3.0.0 before 3.5.0contains a null pointer dereference vulnerabil ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70464 (rsync daemon 2.0.0 before 3.5.0contains a denial of service vulnerabil ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70455 (rsync 3.4.2 before 3.5.0contains a denial of service vulnerability tha ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70453 (rsync before 3.5.0contains an algorithmic complexity vulnerability in ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70452 (rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerabili ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70463 (rsync 3.1.0 before 3.5.0contains an authorization bypass in auth users ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70460 (rsync 2.3.3 before 3.5.0contains a path traversal vulnerability that a ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70462 (rsync 3.1.0 before 3.5.0contains a signed integer overflow vulnerabili ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-70454 (rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 ( ...)
- - rsync <unfixed>
+ - rsync 3.5.0+ds1-1
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-17431 (PDF::WebKit versions through 1.2 for Perl allow OS command injection v ...)
NOT-FOR-US: PDF::WebKit Perl module
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8766c6d27023ee61a088d12624222d5d3ebd9039
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8766c6d27023ee61a088d12624222d5d3ebd9039
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/b53afc1c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list