What is CVE-2026-53801?
CVE-2026-53801 is a symlink race condition vulnerability in rsync's sender directory scanning logic affecting versions before 3.5.0. It allows attackers who can manipulate symlinks to force the sender to enumerate and transfer files outside the intended module root. Users should upgrade to rsync 3.5.0 to mitigate this issue.
Azərbaycanca: CVE-2026-53801, rsync-in 3.5.0-dən əvvəlki versiyalarında göndərənin (sender) kataloq skanlamasında aşkarlanan 'symlink race condition' zəifliyidir. Bu, hücumçuya modulun kök qovluğundan kənar faylları oxutdurub köçürmək imkanı verir. İstifadəçilərə rsync-i 3.5.0 versiyasına yeniləmək tövsiyə olunur.
FAQ2
What software does CVE-2026-53801 affect?
This vulnerability affects rsync versions before 3.5.0.
What can an attacker read using this vulnerability?
An attacker can force the sender to enumerate and transfer files outside the intended module root.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.