What is CVE-2026-53800?
CVE-2026-53800 is a symlink race condition in rsync's --remove-source-files feature prior to version 3.5.0, allowing attackers with symlink creation access to delete arbitrary files. The vulnerability occurs when a symlink is atomically substituted for a source file between transfer completion and the unlink() call. Upgrading rsync to version 3.5.0 or later is necessary to mitigate this issue.
Azərbaycanca: CVE-2026-53800 rsync-in --remove-source-files funksiyasında symlink race condition zəifliyidir. Bu, 3.5.0 versiyasından əvvəlki rsync istifadəçilərinə təsir edir və hücumçulara fayl köçürmə tamamlandıqdan sonra silmə əməliyyatı zamanı simvolik keçid əvəzləməklə ixtiyari fayl silməyə imkan verir. Təhlükəsizlik üçün rsync-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ1
Which versions of rsync are affected by CVE-2026-53800?
All versions of rsync prior to 3.5.0 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.