What is CVE-2026-53797?
This vulnerability is a symlink race condition in the sender's source tree traversal in rsync versions before 3.5.0. An attacker who can manipulate a parent directory of the source tree can redirect file reads to unintended paths. Users are advised to upgrade to rsync 3.5.0 or later.
Azərbaycanca: Bu zəiflik rsync-in 3.5.0-dan əvvəlki versiyalarında göndərən tərəfin mənbə qovluğunu gəzərkən yaranan 'symlink race condition' zəifliyidir. Təcavüzkar mənbə qovluğunun valideyn direktoriyasını manipulyasiya edərək fayl oxuma əməliyyatlarını arzuolunmaz yollara yönləndirə bilər. İstifadəçilərə rsync-i 3.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of rsync are affected by CVE-2026-53797?
This vulnerability affects rsync versions before 3.5.0.
How can I protect against CVE-2026-53797?
Users are advised to upgrade to rsync 3.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.