216.73.216.6

CVE-2026-43619

· Published 20/05/2026 02:16 · Modified 21/05/2026 20:42

Labels: CVE-2026-43619 2026-05-20CVE-2026-43619CWE-59[email protected]

Essential information

Published
20/05/2026 02:16
Modified
21/05/2026 20:42
Author
Creator
CVSS
7.2 HIGH (v3) 7.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
samba / rsync cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*

References