{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-53793: confine the alt-dest basis stat in try_dests and hard_link_check\n- CVE-2026-70458: skip the F_SUM read for ITEM_DELETED in log_formatted",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/advisories/2026/clsa-2026_1789730480.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-18T11:22:20Z",
      "generator": {
        "date": "2026-09-18T11:22:20Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789730480",
      "initial_release_date": "2026-09-18T11:22:20Z",
      "revision_history": [
        {
          "date": "2026-09-18T11:22:20Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "rsync: Fix of 6 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els15?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els13?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els10?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els7?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els6?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                  "product_id": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.0.1.el7_9.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                "product": {
                  "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                  "product_id": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.2-12.el7_9.tuxcare.els4?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        },
        "product_reference": "rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-70453",
      "cwe": {
        "id": "CWE-407",
        "name": "Inefficient Algorithmic Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-70453"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-8x5r-mjx8-83hv",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-8x5r-mjx8-83hv"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-algorithmic-complexity-dos-via-hash-search",
          "url": "https://www.vulncheck.com/advisories/rsync-algorithmic-complexity-dos-via-hash-search"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-70462",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-70462"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-j9wh-5jmp-2m64",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-j9wh-5jmp-2m64"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-signed-integer-overflow-via-msg-io-timeout",
          "url": "https://www.vulncheck.com/advisories/rsync-signed-integer-overflow-via-msg-io-timeout"
        }
      ],
      "release_date": "2026-08-13T15:20:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:20:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-70458",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-70458"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-gg3m-4m9m-268h",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-gg3m-4m9m-268h"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-flag-hlinked-handling",
          "url": "https://www.vulncheck.com/advisories/rsync-out-of-bounds-write-via-flag-hlinked-handling"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-53790",
      "cwe": {
        "id": "CWE-78",
        "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53790"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-5hcf-7xxm-rmqq",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-5hcf-7xxm-rmqq"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-command-injection-via-multiple-code-paths",
          "url": "https://www.vulncheck.com/advisories/rsync-command-injection-via-multiple-code-paths"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-53793",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the module's subtree.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53793"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-wj7w-vh23-mm44",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-wj7w-vh23-mm44"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-path-confinement-bypass-via-boundary-marker-in-chroot-mode",
          "url": "https://www.vulncheck.com/advisories/rsync-path-confinement-bypass-via-boundary-marker-in-chroot-mode"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:19:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-70464",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
        ],
        "known_affected": [
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
          "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-70464"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-hrwq-ccf7-rw5m",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-hrwq-ccf7-rw5m"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-connection-slot-exhaustion-dos-via-handshake-stall",
          "url": "https://www.vulncheck.com/advisories/rsync-connection-slot-exhaustion-dos-via-handshake-stall"
        }
      ],
      "release_date": "2026-08-13T15:20:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-18T11:21:22.237012Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els15.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789730480"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T15:20:00Z",
          "details": "Affected",
          "product_ids": [
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els10.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els2.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els6.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els7.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.0.1.el7_9.tuxcare.els8.x86_64",
            "Red-Hat-7:rsync-0:3.1.2-12.el7_9.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}