What is CVE-2026-53796?
rsync versions before 3.5.0 contain a TOCTOU race condition vulnerability in the non-daemon receiver's destination directory handling. This allows an attacker who can manipulate destination path parent components to redirect file writes to unintended locations. Users should immediately update to rsync version 3.5.0 or later.
Azərbaycanca: rsync-in 3.5.0-dən əvvəlki versiyalarında müştəri (non-daemon receiver) tərəfində TOCTOU (time-of-check to time-of-use) yarış şəraiti zəifliyi aşkarlanıb. Bu, təyinat qovluğunun valideyn komponentlərini manipulyasiya edə bilən hücumçuya fayl yazma əməliyyatlarını nəzərdə tutulmayan yerə yönləndirməyə imkan verir. İstifadəçilərə dərhal rsync-i ən azı 3.5.0 versiyasına yeniləmələri tövsiyə olunur.
FAQ2
Which versions of rsync are affected by CVE-2026-53796?
rsync versions before 3.5.0 contain this TOCTOU race condition vulnerability.
What does an attacker need to manipulate to exploit CVE-2026-53796?
The attacker can manipulate the destination path parent components to redirect file writes to unintended locations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.