| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: rsync | Distribution: openSUSE:Factory:zSystems |
| Version: 3.5.1 | Vendor: openSUSE |
| Release: 1.1 | Build date: Mon Sep 21 14:10:18 2026 |
| Group: Productivity/Networking/Other | Build host: reproducible |
| Size: 1165280 | Source RPM: rsync-3.5.1-1.1.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: https://rsync.samba.org/ | |
| Summary: Versatile tool for fast incremental file transfer | |
Rsync is a fast and extraordinarily versatile file copying tool. It can copy locally, to/from another host over any remote shell, or to/from a remote rsync daemon. It offers a large number of options that control every aspect of its behavior and permit very flexible specification of the set of files to be copied. It is famous for its delta-transfer algorithm, which reduces the amount of data sent over the network by sending only the differences between the source files and the existing files in the destination. Rsync is widely used for backups and mirroring and as an improved copy command for everyday use.
GPL-3.0-or-later
* Mon Sep 21 2026 David Anes <david.anes@suse.com>
- Update to 3.5.1
- Protocol:
- The protocol number was changed to 33.
- Bug fixes:
- Fixed several path-handling regressions from 3.5.0. Explicit
sender paths can again traverse symlinked ancestors without
weakening confinement of paths found during recursive scans.
Local and remote-shell `--files-from` paths are handled as
operator-supplied paths rather than paths beneath the transfer
root.
- Fixed access to `/dev/stdin`, `/dev/stdout`, `/dev/stderr` and
`/dev/fd/N` when they refer to pipes or descriptors inside user
namespaces. Reading batch data from a FIFO or process
substitution works again.
- Restored `--max-alloc=0` as a spelling for the parser's maximum
allocation limit rather than disabling that limit.
- Fixed restricted-root paths in `rrsync` and detection of an
inetd connection when a daemon is started with a local socket on
standard input, as can happen under ADB without a PTY.
- Allowed `--contimeout` for daemon connections made through
`--rsh` without applying it to ordinary remote-shell transfers.
- Tightened validation of partial-directory state and
alternate-destination paths on the receiver. An
alternate-destination leaf symlink is no longer followed as a
basis file.
- Fixed undefined shifts in the bundled zlib code and a FreeBSD
amd64 build failure involving the assembly and SIMD objects.
- Enhancements:
- Added support for internationalised domain names when the
required library is available at build time.
- Added the number of 4 KiB logical blocks touched to `--stats`.
This counts distinct logical file regions written by the
receiver, not physical disk blocks or disk I/O. It is reported
when both peers negotiate protocol 33.
- Build and tests:
- `install-strip` now honours `STRIP` including during
cross-compilation.
- Updated platform tests and fleet-test coverage for the 3.5.0
fixes.
- Activate IDN (internationalised domain name) support by adding
BuildRequires: libidn2-devel
- Drop rsync-fix-protected-regultar-test.patch (already upstream)
* Fri Aug 14 2026 Angel Yankov <angel.yankov@suse.com>
- Fix test suit protected-regular test
* Added rsync-fix-protected-regultar-test.patch
* Thu Aug 13 2026 Marcus Rueckert <mrueckert@suse.de>
- explicitly require python-rpm-macros to not rely on any indirect
requires. Fixes build on SLE 16.0
* Thu Aug 13 2026 Marcus Rueckert <mrueckert@suse.de>
- Update to 3.5.0
- Security update (bsc#1269060, rsync 3.5.0 security backports):
- CVE-2026-53783, bsc#1269041: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist)
- CVE-2026-53784, bsc#1269042: Daemon module-root chdir escape under "use chroot = no"
- CVE-2026-53785, bsc#1269043: --relative implied-parent creation escapes the destination tree
- CVE-2026-53786, bsc#1269044: Daemon --filter merge file bypasses the module filter list
- CVE-2026-53788, bsc#1269046: Daemon name-converter accepts newline-bearing names into its line protocol
- CVE-2026-53789, bsc#1269047: Malicious sender expands --delete scope by reclassifying an implied parent
- CVE-2026-53790, bsc#1269048: Command / argument injection via unquoted peer- or host-controlled values
- CVE-2026-53791, bsc#1269049: PROXY-protocol mode lets a direct client spoof the daemon's source address
- CVE-2026-53792, bsc#1269050: Receiver-supplied zero checksum block length drives sender matching negative
- CVE-2026-53793, bsc#1269051: Chroot "/./" inner-module escape via a parent-component symlink
- CVE-2026-53794, bsc#1269052: Remote peer disables the per-allocation sanity cap via --max-alloc=0
- CVE-2026-53795, bsc#1269053: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement
- CVE-2026-53796, bsc#1269054: Non-daemon receiver destination-chdir symlink race (TOCTOU)
- CVE-2026-53797, bsc#1269055: Sender source-tree parent-component symlink race -> out-of-tree disclosure
- CVE-2026-53798, bsc#1269045: Daemon name-converter empty response maps an unknown name to uid/gid 0
- CVE-2026-53799, bsc#1269056: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation)
- CVE-2026-53800, bsc#1269057: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree
- CVE-2026-53801, bsc#1269058: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure
- CVE-2026-53802, bsc#1269039: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files
- CVE-2026-53803, bsc#1269040: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths
- CVE-2026-70463, bsc#1273430: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule
- CVE-2026-70462, bsc#1273431: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value)
- CVE-2026-70461, bsc#1273432: Peer-driven one-byte heap out-of-bounds write in add_implied_include()
- CVE-2026-70460, bsc#1273433: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink
- CVE-2026-70459, bsc#1273434: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root
- CVE-2026-70458, bsc#1273435: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H
- CVE-2026-70457, bsc#1273436: Attacker-chosen-offset write in parse_size_arg() error formatting
- CVE-2026-70456, bsc#1273437: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs
- CVE-2026-70454, bsc#1273439: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding)
- CVE-2026-70453, bsc#1273440: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain
- CVE-2026-70464, bsc#1273429: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module
- CVE-2026-70455, bsc#1273438: Peer-controlled Zstandard worker exhaustion on an rsync daemon
- CVE-2026-70452, bsc#1273441: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block
- Rejected CVEs (duplicates, resolved to canonical CVEs above):
- CVE-2026-44507, bsc#1271931: duplicate of CVE-2026-43617
- CVE-2026-44508, bsc#1271932: duplicate of CVE-2026-43618
- CVE-2026-44509, bsc#1271933: duplicate of CVE-2026-43619
- CVE-2026-44510, bsc#1271934: duplicate of CVE-2026-43620
- Security update:
- CVE-2025-10158, bsc#1254441: Out of bounds array access via negative index
- CVE-2026-41035, bsc#1262223: count of entries mismatch can lead to a use-after-free
- CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution
- CVE-2026-29518, bsc#1264512: Integer Overflow Information Disclosure
- CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls
- CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files()
- CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing
- SECURITY FIXES:
- This release fixes 33 security issues found during a focused
audit of rsync's path handling and daemon protocol, a
companion daemon-protocol fuzzing pass, and reports from
external researchers -- plus several robustness hardenings.
CVE IDs were assigned by VulnCheck (CNA); the precise
"introduced in" version ranges accompany each advisory, and
many are much narrower than "everything before 3.5.0". Every
fix ships with a regression test in the test suite that fails
on the unfixed tree. Many thanks to the external researchers
credited below.
- Link following (CWE-59/61) -- a local user who controls a
path component plants a symlink that a privileged rsync then
follows:
- CVE-2026-53802 (HIGH): Arbitrary file read / transfer-shaping
via symlinked operator-supplied input files. rsync followed
attacker-planted symlinks in --filter merge files (including
per-directory merges and -C .cvsignore), --files-from /
- -include-from / --exclude-from, and the client
- -password-file / daemon secrets file -- reading an arbitrary
file as filter rules, or sending a victim file's contents as
the daemon authentication response. Operator-supplied paths
are now resolved component-by-component with
openat(O_PATH|O_NOFOLLOW), allowing a symlink component only
when it is owned by uid 0 or the effective uid.
- CVE-2026-53803 (HIGH): Arbitrary file write / privilege
escalation via symlinked operator-supplied output paths --
- -log-file, --write-batch/--read-batch, and the daemon's motd
/ lock / early-input / --config opens. A planted symlink (or
parent component) could redirect the write, e.g. append the
log to authorized_keys; --read-batch could also feed chosen
bytes to the protocol parser. Same trusted-owner path walk,
plus an S_ISREG check on the --read-batch file.
- CVE-2026-53785 (HIGH): Under --relative, the receiver's
implied-parent creation (make_path()) built the parent chain
with a plain mkdir() on the full path, so a planted parent
symlink placed the new directories and file outside the
destination tree. make_path() now creates each component
through the held-directory-fd primitive. Reported by Omar
Elsayed (seks99x).
- CVE-2026-53784 (HIGH): Daemon module-root chdir escape under
use chroot = no: a plain chdir() followed a planted
parent-component symlink, serving files from outside the
module. The module-root chdir now goes through the secure
resolver.
- CVE-2026-53793 (HIGH): Chroot /./ inner-module escape -- a
symlinked parent component inside the inner module reached a
sibling outside it (the generator basis stat, the receiver
write/finish path, the module chdir, and the receiver's
delta-basis open). The secure resolver is now engaged for all
of those paths.
- CVE-2026-53795 (HIGH): An absolute --temp-dir or --link-dest
disabled the receiver's rename/link confinement.
do_rename_at()/do_link_at() bailed to the unconfined
path-based call whenever either path was absolute, so an
absolute source (the temp file, or the link-dest basis) let
finish_transfer()'s tmp->final rename -- or a hard-link
create -- follow a destination parent component an attacker
flipped to a symlink mid-transfer, writing the file outside
the tree. Each side is now confined independently. Reported
by Omar Elsayed (seks99x).
- CVE-2026-53796 (MEDIUM): A non-daemon receiver's one-time
chdir() into the operator-named destination was not fully
confined (a relative destination took a plain chdir()), so an
attacker who raced the named destination from a directory to
a symlink moved the receiver's CWD -- and every file it then
created -- outside the tree. The destination chdir now uses
the same ownership-checked O_NOFOLLOW walk as the daemon
module chdir (see BEHAVIOR CHANGES). Reported by Omar Elsayed
(seks99x).
- CVE-2026-53797 (MEDIUM): A non-daemon sender opened each
transferred file's content by path (leaf O_NOFOLLOW only), so
a source parent component an unprivileged user raced to a
symlink after the file-list scan was followed -- reading a
file from outside the source tree into an attacker-readable
destination. The content open is now anchored at the transfer
root with secure_relative_open(); -L / --copy-unsafe-links /
- k still follow, and --insecure-links restores the legacy
open.
- CVE-2026-53799 (MEDIUM): Receiver ACL/xattr metadata
application followed a symlink race -> arbitrary ACL
set (local privilege escalation). When preserving metadata
(-A/--acls, -X/--xattrs, or fake-super ACL-as-xattr), the
receiver applied each entry's ACL/xattrs by path via
acl_set_file() / setxattr(). A local user who raced a
just-received entry (or a parent) into a symlink before the
apply could redirect an attacker-chosen ACL -- the bytes are
carried in the source entry -- onto a victim inode outside
the destination tree, granting rwx on a root-owned file. The
apply now pins each entry's inode with an O_RDONLY|O_NOFOLLOW
fd and sets all metadata on the held inode (Linux 6.13+
* xattrat syscalls, or a patched libacl's *_at bindings, else
the /proc/self/fd compat path). Where neither primitive
exists (the BSDs, Solaris, macOS, or a /proc-less Linux
container) it falls back to the path-based apply to keep
- -acls functional -- a documented residual, refusable via
refuse options = acls.
- CVE-2026-53800 (MEDIUM): Sender --remove-source-files unlink
followed a parent-component symlink race -> arbitrary
file deletion outside the source tree. The post-send unlink
and its same-file safety re-stat resolved by path relative to
the process CWD, so an unprivileged user who raced a source
parent into a symlink after the file was sent could make a
higher-authority sender (a root --remove-source-files run, or
a daemon module not refusing the option) delete a file
outside the served tree. The removal is now resolved through
the secure held-dirfd walk anchored at the served module root
(daemon) or transfer-root CWD (local sender), the safety
re-stat is confined likewise, and the per-file dev/ino is
only computed when --remove-source-files is in effect.
- CVE-2026-53801 (MEDIUM): Sender/daemon directory-scan
enumeration escaped the transfer root / module ->
out-of-tree disclosure. The sender enumerated each source
directory with a plain opendir() on the accumulated path, not
through the secure resolver (the enumeration sibling of the
previous item, which confined only the content open). A
parent component raced to a symlink between the file-list
scan and the recursive opendir() -- or, in daemon following
mode (-L/--copy-dirlinks/--copy-unsafe-links), an in-module
symlinked directory pointing outside the module -- let a
higher-authority sender enumerate an out-of-tree directory
and copy its entry names, metadata and symlink targets. The
directory scan is now confined through a held opendir fd
anchored at the transfer root / module.
- support/rrsync (the restricted SSH wrapper):
- CVE-2026-53783 (HIGH): rrsync restricted-directory escape. It
validated each argument with realpath() and then exec'd rsync
against the same name (a TOCTOU window), and left dangerous
options enabled in a restricted subdir. rrsync now inode-pins
the validated path and roots the argument it hands rsync at
that pinned fd, denies --copy-unsafe-links, forces --no-D,
and refuses a symlinked --log-file. The pin relies on Linux's
/proc/self/fd magic links being bound to the open inode, so
it is Linux-only; on the BSDs, macOS, Solaris and Cygwin
rrsync passes the realpath()-validated name as it
always did. Two limits are worth stating: under --relative
only the anchor the transmitted name starts from is pinned,
so a component below it can still be raced, and the final
component of an ordinary sender argument is not pinned either
(rsync does not follow a symlink there, and the options that
would change that are refused in a restricted dir).
- A filter rule that failed to parse was echoed back verbatim,
including when the rule came from a merge file's contents. A
per-directory merge rule names a file the peer chooses and
travels over the protocol rather than in an argument, so this
let a peer read back any line of any file the server process
could open that is not valid filter syntax -- through an
rrsync restricted account as well as a daemon module, since
neither confined a merge open that the wrapper never sees. A
syntax error in a rule read from a file now reports the file
and line rather than the text; a rule given as an argument is
still shown. The --debug=FILTER traces print the same
file-derived text, so rrsync now refuses a peer-selected
- -debug (a stock client never sends one). An operator who
turns debugging on for their own server still sees the rule
text.
- Redacting those diagnostics did not close the merge route on
its own, because the worst shape produces no diagnostic at
all: an exclude-only merge (the - modifier) makes every line
of the file a pattern, so nothing fails to parse and the peer
reads the contents off which of its own names went missing
from the file list. Through an rrsync restricted account that
needs no --delete and no verbosity on a pull. The open is now
confined rather than the disclosure suppressed: rsync gained
- -confine-root=DIR, which refuses an operator- or
peer-supplied path that resolves outside DIR, and rrsync
passes its restricted directory. A merge file inside that
directory keeps working. A daemon already had this through
its module root and is unaffected.
- Daemon protocol / identity:
- CVE-2026-53786 (MEDIUM): A client-supplied --filter merge
file bypassed the module filter list (it was checked against
the module-prefixed path, which never matched a module rule).
The module-dir prefix is now stripped before the check.
Reported by Mitchell Benjamin (Revamp Studio).
- CVE-2026-53798 (MEDIUM): The daemon name converter mapped an
unknown name to uid/gid 0 (an empty response was read as
atol("") == 0); with fake super = yes the stored metadata
became root-owned. An empty/non-numeric response is now
treated as a lookup failure. Reported by Mitchell Benjamin
(Revamp Studio).
- CVE-2026-53788 (MEDIUM): A peer-controlled name containing a
newline/CR was written verbatim into the name-converter line
protocol, allowing request injection. Converter tokens
containing control characters are now rejected. Reported by
Mitchell Benjamin (Revamp Studio).
- CVE-2026-53789 (MEDIUM): A malicious daemon-sender could
widen --delete scope by omitting the "no content dir" flag on
an implied parent, making the receiver run delete_in_dir() on
it. Implied-parent directories are now forced non-content on
the receiver. Reported by Mitchell Benjamin (Revamp Studio).
- CVE-2026-53791 (CRITICAL): With proxy protocol = true, a
client connecting directly (not via the trusted proxy) could
send a PROXY header to spoof its source address and bypass
host-based access control. A forwarded address is now
honoured only from a configured trusted-proxy peer.
- Injection and memory safety:
- CVE-2026-53790 (HIGH): Command / argument injection via
unquoted peer- or host-controlled values -- the
RSYNC_CONNECT_PROG %H host substitution, the daemon exec-hook
%RSYNC_*% expansions, rsync-ssl hostspecs, and a missing
newline/CR in remote-shell argument quoting. Each sink is now
quoted or validated (the hook escaping is confined to the
shell-executed hooks, so ordinary daemon string parameters
such as path are unaffected).
- CVE-2026-53792 (MEDIUM): A malicious receiver sending a
checksum header with a block count > 0 but block length == 0
drove the sender's rolling-match arithmetic negative. A zero
block length is now rejected.
- CVE-2026-53794 (MEDIUM): --max-alloc=0 disabled the
per-allocation size cap (the defense behind CVE-2024-12084)
and could be forwarded on the wire to an unpatched daemon. A
zero max-alloc is now rejected at both the client and the
daemon. Reported by Azizcan Dastan (Milenium Security).
- Peer-triggerable memory corruption in the daemon protocol,
found by a daemon-protocol fuzzing pass and reported by Greg
Kroah-Hartman. Each is a WRITE reachable from the wire, which
is why these were split out from the crash-only findings in
the same pass:
- CVE-2026-70461 (HIGH): a one-byte heap out-of-bounds write in
add_implied_include(), driven by a peer-supplied filter rule
whose trailing backslash was not counted when sizing the
copy.
- CVE-2026-70458 (HIGH): an out-of-bounds write from a file
entry marked FLAG_HLINKED that the receiver accepted even
though -H was not in effect, so the hard-link extra slots it
then wrote were never allocated.
- CVE-2026-70456 (HIGH): an out-of-bounds heap write in
read_args() when the peer's argument count lands exactly on
maxargs -- the trailing NULL went one past the end of the
array.
- CVE-2026-70457 (MEDIUM): an attacker-chosen-offset write in
parse_size_arg()'s error formatting, reachable through an
over-large --max-size / --min-size / --max-alloc forwarded to
a daemon.
- CVE-2026-70459 (MEDIUM): a wild-pointer read crashing the
per-connection daemon child, from a crafted first incremental
file list whose transfer root is "." with a non-directory
mode -- parent_ndx stayed 0 while dir_flist was still empty,
so the generator dereferenced a never-written slot. Companion
to CVE-2026-43620; reproduced on released 3.2.7, 3.4.0 and
3.4.1.
- Daemon availability and access control:
- CVE-2026-70464 (HIGH): an unauthenticated peer could complete
the @RSYNCD greeting and then stall forever -- sending a line
with no terminator, or trickling NUL-terminated arguments
into read_args() one byte at a time -- holding a
per-connection child open past the module's max connections
limit. The timeout parameter did not cover it, because
set_io_timeout() ran after the read_args() calls that needed
covering. A separate deadline now spans both, and the
early-protocol argument count is bounded. Reported
independently by Chamal De Silva and by Michal Ruprich (Red
Hat QE).
- CVE-2026-70455 (HIGH): a daemon client could request an
arbitrary Zstandard worker count via --compress-threads; 256
was measured as 257 threads in a single connection. Now
capped at 8 on a daemon, while local and remote-shell
invocations keep the operator's value. Reported, fixed and
tested by Filipe Casal of Trail of Bits, in collaboration
with OpenAI.
- CVE-2026-70453 (HIGH): quadratic CPU exhaustion in
hash_search() from a crafted chain of equal weak checksums.
The chain walk is now bounded. First reported as a
performance problem in public rsync issue #217 by heyciao
(2021); recognised as a security issue, bounded and
regression-tested by Stuart Inglis. This one was already
public and was not embargoed.
- CVE-2026-70452 (HIGH): hosts deny failed OPEN when a
configured hostname could not be resolved -- with forward
lookup enabled, which is the default, an unresolvable deny
token admitted the host it was meant to block. It now fails
closed. Sibling of CVE-2026-43617. Reported by Leonid Bugaev.
- CVE-2026-70463 (HIGH): auth users ignored its documented
comma-only parsing. With a leading comma the split should be
on commas alone, so that a group name containing a space can
be written; it split on whitespace too, so a deny or :ro rule
naming such a group was broken into two meaningless tokens
and never fired. Reported by Andres Berbescu.
- CVE-2026-70460 (HIGH): a peer-supplied --partial-dir or
- -backup-dir was resolved by pathname, so an in-module
symlink could redirect it and place files outside the
daemon's module root. Those paths are now confined. Reported
by Omar Elsayed (seks99x).
- Client-side:
- CVE-2026-70462 (MEDIUM): a peer-supplied MSG_IO_TIMEOUT
defeated the client's own I/O timeout -- a large value
overflowed signed arithmetic, and a non-positive value
disabled the timeout outright. The value is now capped on
receipt and the arithmetic made overflow-safe. Reported by
Z3R0S! (z3r0s6); the non-positive case was reported by Leonid
Bugaev.
- CVE-2026-70454 (MEDIUM): rsync-ssl established an
unauthenticated TLS connection. In stunnel mode it neither
required CA verification nor bound the certificate to the
requested hostname, so an active network attacker could
impersonate the server; the openssl backend had a matching
hostname gap in 3.2.0 through 3.2.3 (found and fixed in 2020
by Matt McCutchen). stunnel mode now requires certificate
verification and hostname binding unless an explicit insecure
opt-out is set, and the GnuTLS backend is refused
conservatively rather than used unverified (Greg
Kroah-Hartman).
- Robustness hardening (no CVE assigned): the RSYNC_PROXY
CONNECT request and proxy response headers are
length-bounded, and peer-requested xattr expansion is capped.
- A second-pass source audit (reported by Leonid Bugaev)
hardened several memory- safety and robustness paths: the
hashtable and file-list size computations are guarded against
a 32-bit integer overflow that a peer's entry count could
otherwise wrap into an under-allocation, and the SIGUSR2
handler is now async-signal-safe (it only sets a flag,
deferring the summary/close-out work to safe poll points).
Separately, the xattr/ACL metadata copy now reads the source
through a held no-follow fd as well as writing the
destination through one -- closing a parent-symlink race on
the --copy-dest and backup source -- and the cross-tree
operator-path metadata apply is now fd-pinned under
- -fake-super too (previously it fell back to a path-based set
for a fake super = yes daemon staging through an absolute
- -temp-dir/--backup-dir).
- SECURITY RELATED:
- Mask a peer-supplied I/O-error value to the defined IOERR_*
bits, both the incoming MSG_IO_ERROR message (io.c) and the
file-list trailer (flist.c), so a malicious peer cannot set
arbitrary (undefined) error flags that would be stored in the
local io_error and re-forwarded upstream. (Undefined bits
never reached the exit code, which maps only the defined
bits.) Reported by Leonid Bugaev.
- Escape control characters in filenames written to the log
file (CWE-117 log injection): a transferred name containing
control bytes -- C0 (tab excepted) and C1 0x80-0x9f,
including CSI 0x9b -- could otherwise inject terminal escape
sequences into an administrator's terminal when the log is
viewed. Reported by Leonid Bugaev.
- Stop safe_arg() leaking an uninitialized byte into a quoted
filename. In filename mode the writer suppresses the escaping
backslash before a wildcard, but the counter that sized the
buffer reserved a slot for every backslash, so the two
disagreed and left an uninitialized heap byte in the returned
string -- which is handed to the remote shell when
- -protect-args is off. The counter now mirrors the writer,
and guarding the wildcard test with f[1] also fixes a
trailing backslash (previously strchr() matched the string
terminator, so the backslash was not doubled). Reported by
Leonid Bugaev.
- Close a --safe-links bypass in --backup: when symlinks can be
hard-linked, make_backup()'s link/rename fast path
hard-linked an unsafe (out-of-tree) symlink into the backup
area and skipped the safe_symlinks check the copy path
applies, silently preserving a link --safe-links was meant to
drop. The safe-links check now runs before the fast path, and
a symlink whose target is unreadable is failed closed rather
than backed up unchecked. Reported by Leonid Bugaev.
- Extend the operator-directory ownership walk to the backup
leaf sinks: do_symlink_at() (backing a symlink up into an
operator --backup-dir) and do_rmdir_at() (removing a
pre-existing backup directory) now resolve their parent
through the same ownership walk, so a foreign-owned parent
symlink no longer redirects the backup symlink-create or
directory-removal outside the backup tree. --insecure-links
(or a module's insecure links = yes) restores the legacy
follow. Reported by Omar Elsayed (seks99x).
- Confine an absolute operator source/destination through the
ownership walk in robust_rename()'s cross-filesystem (EXDEV)
copy fallback, so a raced parent symlink cannot redirect the
fallback copy or its source unlink out of the tree. Reported
by Leonid Bugaev.
- Bound the number of equal-weak-checksum blocks examined per
offset in hash_search() (issue #217), so a crafted or
degenerate checksum set with a very long equal-checksum chain
cannot drive the sender's per-offset match-verify into a
quadratic blow-up (CPU DoS). Fix by Stuart Inglis.
- BUG FIXES:
- Fix an off-by-one in clean_fname()'s ..-collapse path
normalization. Reported by Leonid Bugaev.
- The AVX2 rolling-checksum assembly (--enable-roll-asm) read
up to 64 bytes past the end of the buffer it was given. The
loop is software-pipelined and preloaded the 64 bytes after
the ones it was folding in, so its last iteration always
reached beyond the data -- the remainder is by construction
under 64 bytes. It normally landed in slack inside rsync's
map window and went unnoticed; where the buffer ended at a
page boundary it was a SIGSEGV mid transfer, reported on
macOS x86-64 by Roland Kletzing. Reported checksums are
unchanged.
- --link-dest no longer fails the transfer when the destination
refuses to hard-link a symlink, device node, FIFO or socket.
Whether rsync hard-links those at all was decided at build
time, on whatever filesystem the source tree happened to sit
on, and one host can hold both answers -- macOS builds on
APFS, which can, and backs up to HFS+, which returns ENOTSUP.
Such an entry is now copied, exactly as it already is in a
build that cannot link them and as a regular file in the same
position already was; the run used to exit 23 even though the
entry was then created correctly. The fallback covers any
refusal, since the error does not identify one on its own:
link(2) documents EPERM both for a filesystem without hard
links and for a permission refusal. Still outstanding: under
- H, a group of such entries hard-linked to each other also
needs a link within the destination, and where the
destination cannot hard-link the type at all, the members
after the first are still lost.
- --out-format / --log-file-format now emit a literal % for %%
instead of mis-parsing the following character (added by
Leonid Bugaev); a follow-up bounds log_format_has()'s
width-digit scan to match log_formatted(), closing a %C read
past the checksum field.
- A CVS .cvsignore (or -C) file containing a ! clear-list token
no longer aborts with a spurious "rule has trailing
characters" error. Reported by Leonid Bugaev.
- --chmod=a+s now sets both the setuid and setgid bits,
matching chmod(1) (it previously set setuid only). Reported
by Leonid Bugaev.
- Case-insensitive wildcard matching (used by daemon hosts
allow/hosts deny rules) now folds characters inside a [...]
bracket expression, not just literal pattern characters.
Reported by Leonid Bugaev.
- BEHAVIOR CHANGES:
- A non-daemon receiver follows an operator-named symlinked
destination directory only when the symlink is owned by root
or the running user (e.g. rsync -a src/ /backup/ where
/backup -> /mnt/disk); a destination symlinked by another uid
is now refused, closing a chdir TOCTOU where an attacker
raced the named destination into a symlink. --insecure-links
restores the unconditional follow.
- On platforms without a race-safe way to create a unix socket
in a subdirectory (the BSDs, macOS, Solaris, which lack
bindat()), a nested socket transferred under --specials is
skipped with a warning instead of failing the whole transfer.
Top-level sockets are unaffected.
- proxy protocol = true with no proxy protocol hosts rejects
all connections (fail-closed); the daemon now warns about
this at startup.
- support/rrsync in a restricted subdirectory forces --no-D
(device/special semantics are stripped, so a plain rsync -a
still works) and denies --copy-unsafe-links.
- The path resolver now follows in-tree directory symlinks
uniformly on every platform via a single race-free
per-component O_NOFOLLOW walk, so -K / -L / -k and -R through
an in-tree symlinked parent behave the same everywhere.
- refresh patches
rsync-python-3.6-tests.patch
rsync-usr-etc.patch
rsyncd-return-from-list-command-with-0.patch
- drop rsync-openat2-glibc-missing.patch
- switch to use a modern python on sle 15 for the testsuite
- add use-sys.executable.patch:
don't assume python3 is the binary name. use sys.executable.
* Tue Jun 09 2026 Matej Cepl <mcepl@cepl.eu>
- Add missing python3-base BR
* Thu May 21 2026 David Anes <david.anes@suse.com>
- Fixed some warnings while building the rpm.
- Added patches:
- rsync-python-3.6-tests.patch:
Small patch to support running tests on python 3.6+:
- rsync-openat2-glibc-missing.patch:
Small patch to build on kernels >= 5.6+ where openat2
is not defined in glibc.
- Removed patches already upstream:
- rsync-no-libattr.patch
- rsync-CVE-2025-10158.patch
- rsync-CVE-2026-41035.patch
- rsync341-gcc15-bool.patch
- Removed support for the unmaintained rsync-patches archive,
which in turn removes support for SLP. These patches are not
being shipped anymore.
- Update to 3.4.3:
- SECURITY FIXES:
Six CVEs are fixed in this release. Three of the six
(CVE-2026-29518, CVE-2026-43617, CVE-2026-43619) require
non-default daemon configuration to reach: the first and
third need use chroot = no for a module, the second needs
daemon chroot = ... set in rsyncd.conf.
Two (CVE-2026-43618, CVE-2026-43620) are reachable from a
normal pull or a normal authenticated daemon connection.
The sixth (CVE-2026-45232) is reachable only when RSYNC_PROXY
is set and the proxy (or a MITM) returns a pathological
response.
Complete list of changes: https://download.samba.org/pub/rsync/NEWS#3.4.3
- CVE-2026-29518, bsc#1264511: Symlink-Race TOCTOU in Daemon (use chroot = no)
TOCTOU symlink race condition allowing local privilege
escalation in daemon mode without chroot. An rsync daemon
configured with "use chroot = no" was exposed to a
time-of-check / time-of-use race on parent path components.
- CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution
Hostname/ACL bypass on an rsync daemon configured with
daemon chroot = /X in rsyncd.conf when the chroot tree
lacks DNS resolution support. The reverse-DNS lookup of
the connecting client was performed after the daemon chroot
had been entered; if /X did not contain the libc resolver
fixtures (/etc/resolv.conf, /etc/nsswitch.conf, /etc/hosts,
NSS service modules) the lookup failed and the connecting
hostname was set to "UNKNOWN", causing hostname-based deny
rules to silently fail open. IP-based ACLs are unaffected.
The per-module use chroot setting is unrelated to this
issue. The fix performs the lookup before entering the
daemon chroot.
- CVE-2026-43618, bsc#1264512: Integer Overflow Information Disclosure
Integer overflow in the compressed-token decoder enabling
remote memory disclosure to an authenticated daemon peer.
Workaround for older releases: refuse options = compress in rsyncd.conf.
- CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls
Symlink races on path-based system calls in "use chroot=no"
daemon mode (generalisation of CVE-2026-29518). Earlier
fixes for symlink races on the receiver's open() call
missed the same race class on every other path-based system
call: chmod, lchown, utimes, rename, unlink, mkdir, symlink,
mknod, link, rmdir and lstat.
Default "use chroot = yes" is not exposed.
- CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files()
Out-of-bounds read in the receiver's recv_files() enabling
remote denial-of-service of any client pulling from a
malicious server (incomplete fix of commit 797e17f).
Workaround for older releases: --no-inc-recursive on the client.
- CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy
response parsing
Off-by-one out-of-bounds stack write in the rsync client's
HTTP CONNECT proxy handler (establish_proxy_connection() in
socket.c). The fix detects the "buffer filled without finding
\n" case explicitly by position and refuses the response with
"proxy response line too long".
- In addition to the six CVE fixes, this release adds defence-in-depth
hardening on several adjacent paths.
- BUG FIXES:
- Fixed a regression introduced by the 3.4.0 secure_relative_open().
- Complete list of fixes in version 3.4.2:
- https://download.samba.org/pub/rsync/NEWS#3.4.2
* Thu May 07 2026 David Anes <david.anes@suse.com>
- Security update (CVE-2026-41035, bsc#1262223): rsync: count of
entries mismatch can lead to a use-after-free
- Add rsync-CVE-2026-41035.patch
* Tue Dec 16 2025 David Anes <david.anes@suse.com>
- Security update (CVE-2025-10158, bsc#1254441): rsync: Out of
bounds array access via negative index
- Add rsync-CVE-2025-10158.patch
* Fri Mar 28 2025 Friedrich Haubensak <hsk17@mail.de>
- Add rsync341-gcc15-bool.patch to fix gcc15 compile time error
* Wed Jan 22 2025 Dominique Leuenberger <dimstar@opensuse.org>
- Drop rcFOO symlinks for CODE16 (PED-266).
* Fri Jan 17 2025 ecsos <ecsos@opensuse.org>
- Update to 3.4.1
* BUG FIXES:
- fixed handling of -H flag with conflict in internal flag values
- fixed a user after free in logging of failed rename
- fixed build on systems without openat()
- removed dependency on alloca() in bundled popt
* DEVELOPER RELATED:
- fix to permissions handling in the developer release script
- Drop 705.patch, because now in upstream.
* Thu Jan 16 2025 Andreas Stieger <andreas.stieger@gmx.de>
- update to 3.4.1
* fixed handling of -H flag with conflict in internal flag values
(replaces 705.patch)
* fixed a user after free in logging of failed rename
* fixed build on systems without openat()
* removed dependency on alloca() in bundled popt
* Wed Jan 15 2025 Marcus Rueckert <mrueckert@suse.de>
- Backport patch from PR 705 to fix broken handling of hashes and
hard links:
* Add 705.patch
* Wed Jan 15 2025 Angel Yankov <angel.yankov@suse.com>
- Update to 3.4
* Bump to protocol 32
Drop CVE patches:
* Drop rsync-gcc14.patch
* Removed rsync-CVE-2024-12084-overflow-01.patch
* Removed rsync-CVE-2024-12084-overflow-02.patch
* Removed rsync-CVE-2024-12085.patch
* Removed rsync-CVE-2024-12086_01.patch
* Removed rsync-CVE-2024-12086_02.patch
* Removed rsync-CVE-2024-12086_03.patch
* Removed rsync-CVE-2024-12086_04.patch
* Removed rsync-CVE-2024-12087_01.patch
* Removed rsync-CVE-2024-12087_02.patch
* Removed rsync-CVE-2024-12088.patch
* Removed rsync-CVE-2024-12747.patch
* Tue Jan 14 2025 Angel Yankov <angel.yankov@suse.com>
- Security update,CVE-2024-12747, bsc#1235475 race condition in handling symbolic links
* Added rsync-CVE-2024-12747.patch
* Thu Jan 09 2025 Angel Yankov <angel.yankov@suse.com>
- Security update, fix multiple vulnerabilities:
* CVE-2024-12084, bsc#1234100 - Heap Buffer Overflow in Checksum Parsing
* CVE-2024-12085, bsc#1234101 - Info Leak via uninitialized Stack contents defeats ASLR
* CVE-2024-12086, bsc#1234102 - Server leaks arbitrary client files
* CVE-2024-12087, bsc#1234103 - Server can make client write files outside of destination directory using symbolic links
* CVE-2024-12088, bsc#1234104 - --safe-links Bypass
* Added rsync-CVE-2024-12084-overflow-01.patch
* Added rsync-CVE-2024-12084-overflow-02.patch
* Added rsync-CVE-2024-12085.patch
* Added rsync-CVE-2024-12086_01.patch
* Added rsync-CVE-2024-12086_02.patch
* Added rsync-CVE-2024-12086_03.patch
* Added rsync-CVE-2024-12086_04.patch
* Added rsync-CVE-2024-12087_01.patch
* Added rsync-CVE-2024-12087_02.patch
* Added rsync-CVE-2024-12088.patch
* Fri Sep 06 2024 Marcus Meissner <meissner@suse.com>
- rsync-gcc14.patch: fixed the ipv6 configure check (bsc#1230156)
* Thu Sep 05 2024 Georg Pfuetzenreuter <mail+rpm@georg-pfuetzenreuter.net>
- Add rsyncd-return-from-list-command-with-0.patch to not treat #list as failure
* Mon Aug 26 2024 Thorsten Kukuk <kukuk@suse.com>
- add patch rsync-run-dir.patch:
* Drop dependency on /var/run compat symlink, this causes problems
on image based systems
* Thu May 23 2024 David Anes <david.anes@suse.com>
- Correcly enable SIMD in x64: the flag was renamed from
- -enable-simd to -enable-roll-simd in 3.2.4
- Remove leftovers from previous versions:
* rsync-patches-3.2.7.tar.gz
* rsync-patches-3.2.7.tar.gz.asc
* Thu Apr 18 2024 David Anes <david.anes@suse.com>
- Update to 3.3.0
* BUG FIXES:
- Fixed a bug with --sparse --inplace where a trailing gap in
the source file would not clear out the trailing data in the
destination file.
- Fixed an buffer overflow in the checksum2 code if SHA1 is
being used for the checksum2 algorithm.
- Fixed an issue when rsync is compiled using _FORTIFY_SOURCE so
that the extra tests don't complain about a strlcpy() limit
value (which was too large, even though it wasn't possible for
the larger value to cause an overflow).
(fix bsc#1214616, bsc#1214249)
- Add a backtick to the list of characters that the filename
quoting needs to escape using backslashes.
- Fixed a string-comparison issue in the internal handling of
- -progress (a locale such as tr_TR.utf-8 needed the internal
triggering of --info options to use upper-case flag names to
ensure that they match).
- Make sure that a local transfer marks the sender side as
trusted.
- Change the argv handling to work with a newer popt library
- - one that likes to free more data than it used to.
- Rsync now calls OpenSSL_add_all_algorithms() when compiled
against an older openssl library.
- Fixed a problem in the daemon auth for older protocols
(29 and before) if the openssl library is being used to
compute MD4 checksums.
- Fixed rsync -VV on Cygwin -- it needed a flush of stdout.
- Fixed an old stats bug that counted devices as symlinks.
* ENHANCEMENTS:
- Enhanced rrsync with the -no-overwrite option that allows you
to ensure that existing files on your restricted but writable
directory can't be modified.
- Enhanced the manpages to mark links with .UR & .UE. If your
nroff doesn't support these idioms, touch the file
.md2man-force in the source directory so that md-convert gets
called with the --force-link-text option, and that should
ensure that your manpages are still readable even with the
ignored markup.
- Some manpage improvements on the handling of [global] modules.
- Changed the mapfrom & mapto perl scripts (in the support dir)
into a single python script named idmap. Converted a couple
more perl scripts into python.
- Changed the mnt-excl perl script (in the support dir) into a
python script.
* DEVELOPER RELATED:
- Updated config.guess (timestamp 2023-01-01) and config.sub
(timestamp 2023-01-21).
- Drop rsync-fortified-strlcpy-fix.patch (included upstream).
* Tue Mar 12 2024 Bernhard Wiedemann <bwiedemann@suse.com>
- Avoid package changes in %check
* Wed Nov 29 2023 Stefan Schubert <schubi@suse.com>
- Moved rsyncd.conf and rsyncd.secrets to /usr/etc.
* Add rsync-usr-etc.patch
* Wed Sep 06 2023 David Anes <david.anes@suse.com>
- Rename patch to follow naming patch policies:
fortified-strlcpy-fix.patch -> rsync-fortified-strlcpy-fix.patch
* Wed Sep 06 2023 Thorsten Kukuk <kukuk@suse.com>
- Use "slp" for bcond, not "openslp", like we use for all other
packages, too.
- Disable slp patch and configure option if bcond slp is disabled.
* Tue Sep 05 2023 Dirk Müller <dmueller@suse.com>
- add fortified-strlcpy-fix.patch (bsc#1214616, bsc#1214249)
* Tue Sep 05 2023 Fabian Vogt <fvogt@suse.com>
- Disable openslp support on new distros (bsc#1214884)
* Wed Jul 26 2023 Antonio Teixeira <antonio.teixeira@suse.com>
- Add support directory to %docdir.
Includes some upstream provided scripts such as rrsync. (bsc#1212198)
* Thu Apr 06 2023 Johannes Segitz <jsegitz@suse.com>
- Switch rsyncd symlink to a wrapper script to allow setting a distinct
SELinux type (bsc#1209654)
/usr/bin/rsync /usr/bin/rsync-ssl /usr/bin/rsyncstats /usr/etc/logrotate.d/rsync /usr/etc/rsyncd.conf /usr/etc/rsyncd.secrets /usr/lib/systemd/system/rsyncd.service /usr/lib/systemd/system/rsyncd.socket /usr/lib/systemd/system/rsyncd@.service /usr/sbin/rsyncd /usr/share/doc/packages/rsync /usr/share/doc/packages/rsync/NEWS.md /usr/share/doc/packages/rsync/README.md /usr/share/doc/packages/rsync/support /usr/share/doc/packages/rsync/support/Makefile /usr/share/doc/packages/rsync/support/atomic-rsync /usr/share/doc/packages/rsync/support/cvs2includes /usr/share/doc/packages/rsync/support/deny-rsync /usr/share/doc/packages/rsync/support/file-attr-restore /usr/share/doc/packages/rsync/support/files-to-excludes /usr/share/doc/packages/rsync/support/git-set-file-times /usr/share/doc/packages/rsync/support/idmap /usr/share/doc/packages/rsync/support/install_deps_ubuntu.sh /usr/share/doc/packages/rsync/support/instant-rsyncd /usr/share/doc/packages/rsync/support/json-rsync-version /usr/share/doc/packages/rsync/support/logfilter /usr/share/doc/packages/rsync/support/lsh /usr/share/doc/packages/rsync/support/lsh.sh /usr/share/doc/packages/rsync/support/mnt-excl /usr/share/doc/packages/rsync/support/munge-symlinks /usr/share/doc/packages/rsync/support/nameconvert /usr/share/doc/packages/rsync/support/rrsh.sh /usr/share/doc/packages/rsync/support/rrsync /usr/share/doc/packages/rsync/support/rrsync.1.md /usr/share/doc/packages/rsync/support/rsync-no-vanished /usr/share/doc/packages/rsync/support/rsync-slash-strip /usr/share/doc/packages/rsync/support/rsyncstats /usr/share/doc/packages/rsync/support/savetransfer.c /usr/share/doc/packages/rsync/tech_report.tex /usr/share/licenses/rsync /usr/share/licenses/rsync/COPYING /usr/share/man/man1/rsync-ssl.1.gz /usr/share/man/man1/rsync.1.gz /usr/share/man/man5/rsyncd.conf.5.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Sep 29 22:49:03 2026