[CLSA-2026:1779822401] rsync: Fix of CVE-2026-29518
Type:
security
Severity:
Important
Release date:
2026-05-26 19:06:50 UTC
Description:
- CVE-2026-29518: fix sender read-path TOCTOU by routing the daemon open through secure_relative_open() from the trusted module_dir root
Updated packages:
  • rsync-3.2.5-3.el9_6.tuxcare.els5.x86_64.rpm
    sha:de1dc719c12288b78dea297f445698418175eee3144ea2361fa86fdb980e6369
  • rsync-daemon-3.2.5-3.el9_6.tuxcare.els5.noarch.rpm
    sha:7c380046288c60cc63656ebf424ee5d8ec681d453eae2f1cacb130bc5273a870
  • rsync-rrsync-3.2.5-3.el9_6.tuxcare.els5.noarch.rpm
    sha:cc78502f7e6236384be5b68f6d8616bfb33ea41105c3500b3a921d9e4fcdf5d1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.