Accepted rsync 3.5.0+ds1-1 (source) into unstable
Debian FTP Masters <[email protected]>
| Newsgroups | gmane.linux.debian.devel.changes.unstable |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Aug 2026 11:00:00 -0700 Source: rsync Architecture: source Version: 3.5.0+ds1-1 Distribution: unstable Urgency: medium Maintainer: Samuel Henrique <[email protected]> Changed-By: Samuel Henrique <[email protected]> Changes: rsync (3.5.0+ds1-1) unstable; urgency=medium . [ Sylvain Beucler ] * autopkgtest improvements * Drop allow-stderr autopkgtest restriction . [ Samuel Henrique ] * New upstream version 3.5.0+ds1, fixing 33 CVEs: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) - CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" - CVE-2026-53785: --relative implied-parent creation escapes the destination tree - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative - CVE-2026-53793: Chroot "/./" inner-module escape via a parent-component symlink - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding) - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value) - CVE-2026-70463: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module * d/p/skip_devices_test_non_linux.patch: Drop patch applied upstream * d/patches: - Pull 3 patches for regression fixes: ~ Honor_STRIP_in_install-strip_for_cross-compilation.patch ~ rrsync_support_fd_pins_in_user_namespaces.patch ~ testsuite_bound_the_unshare_probe.patch * d/rsync.NEWS: Add a NEWS entry about all the behavior changes Checksums-Sha1: 58a757b93018bf66f23f7beb1f79ee569f834b5f 2169 rsync_3.5.0+ds1-1.dsc a7825c2f75be948bc1c9ad145f4273ca9a074751 1135808 rsync_3.5.0+ds1.orig.tar.xz fd7fd96cabc33ebb71e3a435acc529262181608d 40276 rsync_3.5.0+ds1-1.debian.tar.xz c14dcb53ca110be27576293ff71fcd38f3da5422 6659 rsync_3.5.0+ds1-1_amd64.buildinfo Checksums-Sha256: 8708c90eb4fd9e78545c0826a7998e48e48c1576f456dce11b0b5ef5f331546a 2169 rsync_3.5.0+ds1-1.dsc d5de0c8a95b00e0f50038ba04526bcbd5fe4f3ff97b4035bb97b084398bfbb60 1135808 rsync_3.5.0+ds1.orig.tar.xz 0b8f3724063648e31f2e0ee0c674849bcfe76f5396093cead91e6f0ebade85ce 40276 rsync_3.5.0+ds1-1.debian.tar.xz 4bc32bbb075a54ed8019c92a6540b5f386bc3c3755206805e3c5d251f4f875fe 6659 rsync_3.5.0+ds1-1_amd64.buildinfo Files: 71904f53e7a633ad9614012b8dc906f1 2169 net optional rsync_3.5.0+ds1-1.dsc 535745943fddf1b8113773a00fcedb06 1135808 net optional rsync_3.5.0+ds1.orig.tar.xz d5527134b3ce5b830d9a53e6d8bb4074 40276 net optional rsync_3.5.0+ds1-1.debian.tar.xz 0987e373c28987d7d6388a1a396a0be6 6659 net optional rsync_3.5.0+ds1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBdtqg34QX0sdAsVfu6n6rcz7RwcFAmqCeuQACgkQu6n6rcz7 RweSlRAAq0I3SXdkqMNK+CufkXSEZF7cl4WcMYZA5uqA3D75WtZS/p/N9H+ceAbX ZqqjPF53LDlJFEUCS3PU5d9aC/fMx6O7AcQYHPLAR1aZweaJwC0bwl3PK8G6o9Fz TY0wyvgbGmPoutci/j67poSViTzaywcaFV8U8QiczlHtRQbX3nXCR9uXDzUFCD3/ PGoNqQ6F293RM1LVKoKxq0adwAuoxR4yJM7ENY2v6Jz2WQ/+p5cAC5jTQLu1RQdQ 477teDoCKwnXkIM1CKa8tixp1C9JMfNOraXSTfqJet91NoVRpWvzc0uR+OyfhMde VeZAA7bODJOsWhPsSNk8Pt/roW+yIxwkRwEleJoxFvPpkglLHkAVwiqY7DhNNlQ2 zFYGkW4OPGuY/WjcRqRT4JuBbibwECciVPQqXYQniRmEHUZD2CC01AHKlzqjQ3NT Y7DNg7L7F9p0+7ozif1RsOoautrfX5I/myDBglzLwd+mf+ATQ84jSA8svV4hp2hm 6CtGfjQMRuvTDxyXTr+mGtcSsQttdPTHLt3EcMc8rSujc+KUrpXU9eucJXHYwVTR CtupTzGIPWBnVi0nPNoWyoT3+D0ORRhpC66Q4XRoMSbOh2WAl9d40L6zlizO8VZL tG76zGb0r9fwGGyagYZftxed1d9zqIhpQ9dNBwYn8jc1tVoYxgY= =i60q -----END PGP SIGNATURE-----
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaoKBIgAKCRCb9qggYcy5 IVVCAQDc9uO0lv/8erm7Ka2DmXpkVC24AWf0hPW11aq6Vqi5fAD/aXwLKI4+JdSQ 8YhwyhwQTK0IajXXsZBJHf3ZJssBtww= =9QD8 -----END PGP SIGNATURE-----