CVE-2026-53785

NameCVE-2026-53785
Descriptionrsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rsync (PTS)bookworm3.2.7-1+deb12u6vulnerable
bookworm (security)3.2.7-1+deb12u5vulnerable
trixie3.4.1+ds1-5+deb13u4vulnerable
trixie (security)3.4.1+ds1-5+deb13u3vulnerable
forky, sid3.5.0+ds1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rsyncsource(unstable)3.5.0+ds1-1

Notes

https://download.samba.org/pub/rsync/NEWS#3.5.0

Search for package or bug name: Reporting problems