rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rsync | Sep 1, 2026 | Aug 13, 2026 |
| Freebsd | — | Upgrade rsync | Aug 27, 2026 | Aug 25, 2026 |
| Redhat_linux | — | No solution existsUpgrade rsyncUpgrade rsync-daemonUpgrade rsync-rrsyncUpgrade rsync-debugsourceUpgrade rsync-debuginfo | Aug 25, 2026 | Aug 13, 2026 |
| Rocky_linux | — | Upgrade rsyncUpgrade rsync-debuginfoUpgrade rsync-debugsource | Sep 17, 2026 | Sep 15, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub