Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Slackware 15.0 Rsync Major Security Update for Privilege Escalation DoS

slackware
Calendar Grey May 20, 2026
Dist Slackware Esm H88
New rsync packages for Slackware 15.0 fix critical security issues including privilege escalation and DoS.
New rsync packages are available for Slackware 15.0 and -current to fix security issues.

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/rsync-3.4.3-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. Hostname/ACL bypass on an rsync daemon configured with `daemon chroot = /X` in rsyncd.conf when the chroot tree lacks DNS resolution support. Integer overflow in the compressed-token decoder enabling remote memory disclosure to an authenticated daemon peer. Symlink races on path-based system calls in "use chroot = no" daemon mode. Out-of-bounds read in the receiver's recv_files() enabling remote denial-of-service of any client pulling from a malicious server. Off-by-one out-of-bounds stack write in the rsync client's HTTP CONNECT proxy handler (`establish_proxy_connection()` in `socket.c`). For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-29518

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you.
Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/rsync-3.4.3-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/rsync-3.4.3-x86_64-1_slack15.0.txz
Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/rsync-3.4.3-i686-1.txz
Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/rsync-3.4.3-x86_64-1.txz

MD5 Signatures

Slackware 15.0 package: 89c174591e23e2bd164e3ac9b152b21e rsync-3.4.3-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: c6db038250d687970e1f039efb040e45 rsync-3.4.3-x86_64-1_slack15.0.txz
Slackware -current package: 648608b442b5ea5d03e60d4276e78755 n/rsync-3.4.3-i686-1.txz
Slackware x86_64 -current package: 542590e7c3365b568d47b3e4c3de9773 n/rsync-3.4.3-x86_64-1.txz

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg rsync-3.4.3-i586-1_slack15.0.txz

Your message here