What is CVE-2026-53798?
CVE-2026-53798 is a privilege confusion vulnerability in the name-converter subprocess of rsync versions before 3.5.0, where uid/gid mapping flaws allow local attackers to manipulate name-converter responses to return empty values, causing transferred files to be owned by root. Affected users should immediately update rsync to version 3.5.0 or later to mitigate this issue.
Azərbaycanca: CVE-2026-53798 zəifliyi rsync-in 3.5.0 versiyasından əvvəlki versiyalarında "name-converter" alt prosesində imtiyaz qarışıqlığı (privilege confusion) yaradır. Bu, lokal hücumçuların name-converter cavablarını manipulyasiya edərək köçürülən faylların root istifadəçisinə məxsus olmasına səbəb ola bilər. Təsirlənən sistemlərdə dərhal rsync-i 3.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which software and versions are affected by CVE-2026-53798?
This vulnerability affects versions of rsync prior to 3.5.0.
How can users protect themselves from CVE-2026-53798?
Affected users should immediately update rsync to version 3.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.