VDB
GCVE-110-MAGEIA-2026-265
GCVE-110-MAGEIA-2026-265
Advisory Published
The updated package fixes security vulnerabilities:
Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File
Write. (CVE-2026-29518)
Rsync < 3.4.3 Authorization Bypass via Hostname Resolution.
(CVE-2026-43617)
Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618)
Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls.
(CVE-2026-43619)
Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files().
(CVE-2026-43620)
Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | rsync | 0 (affected), 3.2.7-1.5.mga9 (unaffected) | — |
| Mageia | rsync | 0 (affected), 3.4.1-4.1.mga10 (unaffected) | — |
References
Browse GCVE Records
68,083 records in the GCVE database · Updated August 18, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.