目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-53796— RsyncProject Rsync 竞争条件问题漏洞

CVSS 6.3 · Medium EPSS 0.09% · P1

Affected Version Matrix 2

ベンダープロダクトVersion Rangeステータス
RsyncProjectrsync≤ 3.4.4affected
3.5.0unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-53796の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling
ソース: CVE Program / CVE List V5
脆弱性説明
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Attackers can substitute a symlink for a component of the destination path between the path resolution and chdir() call, causing the receiver's working directory to be established outside the intended destination tree so that subsequent relative-path file writes land in unintended filesystem locations.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
在文件访问前对链接解析不恰当(链接跟随)
ソース: CVE Program / CVE List V5
脆弱性タイトル
RsyncProject Rsync 竞争条件问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
RsyncProject Rsync是RsyncProject组织开源的一款速度快、功能极其强大的文件复制工具,可用于复制远程文件和本地文件。 RsyncProject Rsync 3.5.0之前版本存在安全漏洞,该漏洞源于非守护进程接收器的目标目录处理存在TOCTOU竞争条件问题,允许攻击者操纵目标路径父组件,在路径解析和chdir()调用之间替换符号链接,将文件写入重定向到意外位置。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
RsyncProjectrsync 0 ~ 3.4.4 -

II. CVE-2026-53796の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-53796のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-53796 厂商安全公告 (2)

CVE-2026-53796 厂商页面 (1)

Same Patch Batch · RsyncProject · 2026-08-13 · 33 CVEs total

CVE-2026-537919.1 CRITICALrsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
CVE-2026-704618.2 HIGHrsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
CVE-2026-704568.2 HIGHrsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()
CVE-2026-704588.2 HIGHrsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling
CVE-2026-704638.1 HIGHrsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
CVE-2026-537908.1 HIGHrsync < 3.5.0 Command Injection via Multiple Code Paths
CVE-2026-537958.1 HIGHrsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest
CVE-2026-704608.1 HIGHrsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
CVE-2026-537838.1 HIGHrsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync
CVE-2026-704548.0 HIGHrsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode
CVE-2026-538037.8 HIGHrsync < 3.5.0 Symlink Following Arbitrary File Overwrite
CVE-2026-704557.5 HIGHrsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
CVE-2026-704647.5 HIGHrsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall
CVE-2026-704537.5 HIGHrsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
CVE-2026-704527.4 HIGHrsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2026-537937.4 HIGHrsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
CVE-2026-538027.1 HIGHrsync < 3.5.0 Arbitrary File Read via Symlink Following
CVE-2026-537847.1 HIGHrsync < 3.5.0 Path Traversal via Symlink Module Root
CVE-2026-537857.1 HIGHrsync < 3.5.0 Path Traversal Write Escape via --relative Mode
CVE-2026-704626.5 MEDIUMrsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT

Showing 20 of 33 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-53796へのコメント

まだコメントはありません


コメントを残す