What is CVE-2026-53793?
rsync versions before 3.5.0 contain a path confinement bypass vulnerability allowing remote clients to escape the chroot boundary using `/./` markers in the module root. Users should immediately update rsync to version 3.5.0 to mitigate the risk.
Azərbaycanca: rsync 3.5.0-dən əvvəlki versiyalar "path confinement bypass" boşluğu var. Bu, uzaqdan qoşulan istifadəçilərə modul kökündə `/./` markeri olduqda chroot sərhədini keçməyə imkan verir. İstifadəçilər rsync-i dərhal 3.5.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What is CVE-2026-53793 in rsync?
It is a path confinement bypass vulnerability in rsync versions before 3.5.0. This flaw allows remote clients to escape the chroot boundary if the module root contains a `/./` marker.
How to protect against the CVE-2026-53793 vulnerability?
Users should immediately update rsync to version 3.5.0 to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.