Ubuntu alert USN-8349-3 (rsync)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8349-3] rsync regression | |
| Date: | Tue, 16 Jun 2026 09:38:08 +0000 | |
| Message-ID: | <E1wZQFF-0006AO-01@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8349-3 June 16, 2026 rsync regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: USN-8349-1 introduced regressions in rsync. Software Description: - rsync: fast, versatile, remote (and local) file-copying tool Details: USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple regressions in rsync functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Calum Hutton discovered that rsync contained a heap-based out-of-bounds read when handling file transfers. A remote attacker with read access to an rsync server could possibly use this issue to cause a denial of service. (CVE-2025-10158) Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that rsync daemons configured without chroot protection were exposed to a race condition on parent path components. A local attacker with write access to a module could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-29518) It was discovered that rsync did not properly validate a length value while sorting extended attributes. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41035) It was discovered that rsync performed reverse-DNS lookups after chrooting in some daemon configurations. A remote attacker could possibly use this issue to bypass hostname-based access controls and access network services. (CVE-2026-43617) Omar Elsayed discovered that rsync did not properly check for integer overflows while decoding compressed tokens. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-43618) Andrew Tridgell discovered that rsync did not fully fix a symlink race condition in path-based system calls for daemons configured without chroot protection. A local attacker could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-43619) Pratham Gupta discovered that rsync did not properly validate an index while processing file lists. A remote attacker could possibly use this issue to cause rsync to crash, resulting in a denial of service. (CVE-2026-43620) Michal Ruprich discovered that rsync contained an off-by-one error while handling HTTP proxy responses. An attacker able to intercept network communications or a malicious proxy server could possibly use this issue to cause a denial of service. (CVE-2026-45232) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS rsync 3.1.3-8ubuntu0.9+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS rsync 3.1.2-2.1ubuntu1.6+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS rsync 3.1.1-3ubuntu1.3+esm6 Available with Ubuntu Pro Ubuntu 14.04 LTS rsync 3.1.0-2ubuntu0.4+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. After a standard system update you need to restart rsync daemons to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8349-3 https://ubuntu.com/security/notices/USN-8349-2 https://ubuntu.com/security/notices/USN-8349-1 https://launchpad.net/bugs/2155874
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoxGJEACgkQcpJm3tlz hgENxA/+OExeMEp5t9mjCHP0QlB19FX6Sf7ZhU998otwm0YqMm4GlDqYSkfVKtV8 Ct8Szs2hhY6EEN3uXZm4sf3Xtpewb7bYhRfmH8LTw38GmVJLuKj6QguczGYeeiEP U3LmflRSh5DrcM+xAMuHGlFimuRZWvLWIDfo6oxVKt5bgjELyPFGLuj5X4deQxyA CIWpJBuHOlHU+plE+zFTVbPj22CuicExLtocV9k63sbCy1MK76VYY2AddPECZqkg gylqqTU70sSfGqlwCKck+uEA7bwSIen3ZbnjflYjgdx+iK/Tf6IHUsw8DzRPGc7c DuCdA8V0dLQgRsUAi1FgkqaYpn4REkDKYNqvlmRHgyXIO2aFiDLTVXdlWxCimnQA FqJ29lnVNgFyMaMiGDuZN3neG6rRPsCPVFwJaVVd1xIhuRx1MpcPlckqi4MuWHQo unqnMz7RXtkfo9MKaBNNA9YY6NHF4ekvoln33o+bhV8BBXrXeTr7MvWokPhF22fP 4Khd+l7o4c3R+BqiP5omAmzNXSHwkU6BtrwnVTqgk/tpr6nmq1WvcLDcWmm1HO84 DBUJ82mrWihCvZKMRanEdgnUGrrt4C12u9y2CZy/RaGHWHUlZIW+MIIqsdzEVI6u VEI5gO5GP+Z8HZ4mv7mHRLhAz6UCqFjITZRV8yS0dq1YzjYmiCA= =H6v1 -----END PGP SIGNATURE-----
