VDB

GCVE-110-MAGEIA-2026-265

GCVE-110-MAGEIA-2026-265
Advisory Published
Vulnetix · Advisory published July 18, 2026
The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232)

Affected Products

VendorProductVersionsPlatforms
Mageiarsync0 (affected), 3.2.7-1.5.mga9 (unaffected)
Mageiarsync0 (affected), 3.4.1-4.1.mga10 (unaffected)

Browse GCVE Records

68,083 records in the GCVE database · Updated August 18, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›