Skip to content

GHSA-p4c5-8c68-5fjq on Cyberus Linux 26.05

Aliases: GHSA-p4c5-8c68-5fjq, CVE-2026-53788

Packages: rsync

Status: In Progress

Advisory Information

A peer-controlled name containing a newline/CR was written verbatim into the name-converter helper's persistent line protocol, allowing request injection into that channel.

Fix: reject converter tokens containing control characters.

Test: daemon-namecvt-newline-token.

Credit: Mitchell Benjamin (Revamp Studio).

Affected: rsync 3.4.3 and earlier; fixed in 3.5.0. (Precise introduced-in ranges being finalised.)

Updates

2026-08-31 17:32 CEST

Metadata changes:

  • Status for package rsync: “In Progress” (9b9ebeee7b4bd3be63ce8cc0a23b403542478f68)

2026-08-14 16:57 CEST

Metadata changes:

  • Status for package rsync: “Plausible

2026-08-14 16:55 CEST

Metadata changes:

  • Status for package rsync: “New