{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2026/cve-2026-53798-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-18T13:36:39Z",
      "generator": {
        "date": "2026-09-18T13:36:39Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-53798-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2026-08-13T15:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-13T15:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-17T12:45:34Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-09-18T13:36:39Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-53798"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53798",
      "cwe": {
        "id": "CWE-704",
        "name": "Incorrect Type Conversion or Cast"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53798"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-hx7p-3gvv-pqgv",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-hx7p-3gvv-pqgv"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-privilege-confusion-via-name-converter-uid-gid-mapping",
          "url": "https://www.vulncheck.com/advisories/rsync-privilege-confusion-via-name-converter-uid-gid-mapping"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-03T15:15:54.574665Z",
          "details": "This issue is only reachable when rsync is run as a daemon with two non-default settings enabled together: a configured “name-converter” helper and “fake super,” and it further requires a local ability to influence the helper’s responses—conditions that are atypical for routine rsync-over-SSH or default rsyncd use. Even if present, the effect is limited to metadata integrity (file ownership on the destination) with no confidentiality or availability impact. Given these specific configuration prerequisites, the local attack requirement, and the metadata-only scope, it can be safely deprioritized in managed VM/server environments.",
          "product_ids": [
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
          ]
        }
      ]
    }
  ]
}