Accepted rsync 3.5.0+ds1-1 (source) into unstable

Debian FTP Masters <[email protected]>
Newsgroups gmane.linux.debian.devel.changes.unstable
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 16 Aug 2026 11:00:00 -0700
Source: rsync
Architecture: source
Version: 3.5.0+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Samuel Henrique <[email protected]>
Changed-By: Samuel Henrique <[email protected]>
Changes:
 rsync (3.5.0+ds1-1) unstable; urgency=medium
 .
   [ Sylvain Beucler ]
   * autopkgtest improvements
   * Drop allow-stderr autopkgtest restriction
 .
   [ Samuel Henrique ]
   * New upstream version 3.5.0+ds1, fixing 33 CVEs:
     - CVE-2026-53783: rrsync restricted-directory escape
       (validation-vs-exec race + unsafe option allowlist)
     - CVE-2026-53784: Daemon module-root chdir escape under "use chroot =
       no"
     - CVE-2026-53785: --relative implied-parent creation escapes the
       destination tree
     - CVE-2026-53786: Daemon --filter merge file bypasses the module filter
       list
     - CVE-2026-53788: Daemon name-converter accepts newline-bearing names
       into its line protocol
     - CVE-2026-53789: Malicious sender expands --delete scope by
       reclassifying an implied parent
     - CVE-2026-53790: Command / argument injection via unquoted peer- or
       host-controlled values
     - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the
       daemon's source address
     - CVE-2026-53792: Receiver-supplied zero checksum block length drives
       sender matching negative
     - CVE-2026-53793: Chroot "/./" inner-module escape via a
       parent-component symlink
     - CVE-2026-53794: Remote peer disables the per-allocation sanity cap
       via --max-alloc=0
     - CVE-2026-53795: Receiver write escape via an absolute --temp-dir /
       --link-dest disabling rename/link confinement
     - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race
       (TOCTOU)
     - CVE-2026-53797: Sender source-tree parent-component symlink race ->
       out-of-tree disclosure
     - CVE-2026-53798: Daemon name-converter empty response maps an unknown
       name to uid/gid 0
     - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race
       -> arbitrary ACL set (local privilege escalation)
     - CVE-2026-53800: Sender --remove-source-files unlink follows a
       parent-component symlink race -> arbitrary file deletion outside the
       source tree
     - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the
       transfer root / module -> out-of-tree disclosure
     - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked
       operator-supplied input files
     - CVE-2026-53803: Arbitrary file write / privilege escalation via
       symlinked operator-supplied output paths
     - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname
       cannot be resolved, admitting the host it was meant to block
     - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a
       crafted equal-weak-checksum chain
     - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS
       connection (no CA verification; no stunnel hostname binding)
     - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an
       rsync daemon
     - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when
       the argument count lands exactly on maxargs
     - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg()
       error formatting
     - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry
       accepted without -H
     - CVE-2026-70459: Per-connection daemon child crash from a crafted
       first incremental file list with a non-directory transfer root
     - CVE-2026-70460: Daemon module-root escape through a peer-supplied
       --partial-dir / --backup-dir resolving via an in-module symlink
     - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in
       add_implied_include()
     - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own
       I/O timeout (signed overflow, and a non-positive value)
     - CVE-2026-70463: "auth users" ignores documented comma-only parsing,
       silently skipping a deny/read-only rule
     - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out
       an rsync daemon module
   * d/p/skip_devices_test_non_linux.patch: Drop patch applied upstream
   * d/patches:
      - Pull 3 patches for regression fixes:
        ~ Honor_STRIP_in_install-strip_for_cross-compilation.patch
        ~ rrsync_support_fd_pins_in_user_namespaces.patch
        ~ testsuite_bound_the_unshare_probe.patch
   * d/rsync.NEWS: Add a NEWS entry about all the behavior changes
Checksums-Sha1:
 58a757b93018bf66f23f7beb1f79ee569f834b5f 2169 rsync_3.5.0+ds1-1.dsc
 a7825c2f75be948bc1c9ad145f4273ca9a074751 1135808 rsync_3.5.0+ds1.orig.tar.xz
 fd7fd96cabc33ebb71e3a435acc529262181608d 40276 rsync_3.5.0+ds1-1.debian.tar.xz
 c14dcb53ca110be27576293ff71fcd38f3da5422 6659 rsync_3.5.0+ds1-1_amd64.buildinfo
Checksums-Sha256:
 8708c90eb4fd9e78545c0826a7998e48e48c1576f456dce11b0b5ef5f331546a 2169 rsync_3.5.0+ds1-1.dsc
 d5de0c8a95b00e0f50038ba04526bcbd5fe4f3ff97b4035bb97b084398bfbb60 1135808 rsync_3.5.0+ds1.orig.tar.xz
 0b8f3724063648e31f2e0ee0c674849bcfe76f5396093cead91e6f0ebade85ce 40276 rsync_3.5.0+ds1-1.debian.tar.xz
 4bc32bbb075a54ed8019c92a6540b5f386bc3c3755206805e3c5d251f4f875fe 6659 rsync_3.5.0+ds1-1_amd64.buildinfo
Files:
 71904f53e7a633ad9614012b8dc906f1 2169 net optional rsync_3.5.0+ds1-1.dsc
 535745943fddf1b8113773a00fcedb06 1135808 net optional rsync_3.5.0+ds1.orig.tar.xz
 d5527134b3ce5b830d9a53e6d8bb4074 40276 net optional rsync_3.5.0+ds1-1.debian.tar.xz
 0987e373c28987d7d6388a1a396a0be6 6659 net optional rsync_3.5.0+ds1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBdtqg34QX0sdAsVfu6n6rcz7RwcFAmqCeuQACgkQu6n6rcz7
RweSlRAAq0I3SXdkqMNK+CufkXSEZF7cl4WcMYZA5uqA3D75WtZS/p/N9H+ceAbX
ZqqjPF53LDlJFEUCS3PU5d9aC/fMx6O7AcQYHPLAR1aZweaJwC0bwl3PK8G6o9Fz
TY0wyvgbGmPoutci/j67poSViTzaywcaFV8U8QiczlHtRQbX3nXCR9uXDzUFCD3/
PGoNqQ6F293RM1LVKoKxq0adwAuoxR4yJM7ENY2v6Jz2WQ/+p5cAC5jTQLu1RQdQ
477teDoCKwnXkIM1CKa8tixp1C9JMfNOraXSTfqJet91NoVRpWvzc0uR+OyfhMde
VeZAA7bODJOsWhPsSNk8Pt/roW+yIxwkRwEleJoxFvPpkglLHkAVwiqY7DhNNlQ2
zFYGkW4OPGuY/WjcRqRT4JuBbibwECciVPQqXYQniRmEHUZD2CC01AHKlzqjQ3NT
Y7DNg7L7F9p0+7ozif1RsOoautrfX5I/myDBglzLwd+mf+ATQ84jSA8svV4hp2hm
6CtGfjQMRuvTDxyXTr+mGtcSsQttdPTHLt3EcMc8rSujc+KUrpXU9eucJXHYwVTR
CtupTzGIPWBnVi0nPNoWyoT3+D0ORRhpC66Q4XRoMSbOh2WAl9d40L6zlizO8VZL
tG76zGb0r9fwGGyagYZftxed1d9zqIhpQ9dNBwYn8jc1tVoYxgY=
=i60q
-----END PGP SIGNATURE-----
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaoKBIgAKCRCb9qggYcy5
IVVCAQDc9uO0lv/8erm7Ka2DmXpkVC24AWf0hPW11aq6Vqi5fAD/aXwLKI4+JdSQ
8YhwyhwQTK0IajXXsZBJHf3ZJssBtww=
=9QD8
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.