What is CVE-2026-53799?
CVE-2026-53799 is a symlink race condition vulnerability in rsync versions before 3.5.0. It allows local attackers to apply arbitrary ACLs or extended attributes to unintended files by replacing a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Upgrading rsync to version 3.5.0 or later is recommended.
Azərbaycanca: CVE-2026-53799 rsync-in 3.5.0 versiyasından əvvəlki versiyalarında aşkarlanmış symlink race condition zəifliyidir. Bu, lokal hücumçulara fayl yazma və acl_set_file()/lsetxattr() çağırışları arasında simvolik keçid əvəzləyərək ixtiyari ACL və ya genişləndirilmiş atributları hədəf fayllara tətbiq etməyə imkan verir. rsync-i ən azı 3.5.0 versiyasına yeniləmək tövsiyə olunur.
FAQ2
What privileges does an attacker need to exploit CVE-2026-53799?
CVE-2026-53799 is a vulnerability that can be exploited by local attackers.
What should be done to remediate CVE-2026-53799?
Upgrading rsync to version 3.5.0 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.