An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for rsync ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20754-1 Rating: important References: * bsc#1254441 * bsc#1262223 Cross-References: * CVE-2025-10158 * CVE-2026-41035 CVSS scores: * CVE-2025-10158 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-41035 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41035 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for rsync fixes the following issues - CVE-2025-10158: Out of bounds array access via negative index (bsc#1254441). - CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-749=1 Package List: - openSUSE Leap 16.0: rsync-3.4.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-10158.html * https://www.suse.com/security/cve/CVE-2026-41035.html . Critical update for openSUSE resolves important issues in rsync addressing use-after-free and out of bounds access.. openSUSE security update, rsync vulnerabilities, important patch fix, out of bounds access, use-after-free. . Severity: Important. LinuxSecurity.com Team
Moderate: rsync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6825", "synopsis": "Moderate: rsync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rsync.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.\n\nSecurity Fix(es):\n\n* rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2415637", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2415637", "description": ""}], "cves": [{"name": "CVE-2025-10158", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-10158", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-129"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["rsync-daemon-0:3.4.1-2.el10_1.2.noarch.rpm", "rsync-debugsource-0:3.4.1-2.el10_1.2.aarch64.rpm", "rsync-0:3.4.1-2.el10_1.2.x86_64.rpm", "rsync-0:3.4.1-2.el10_1.2.src.rpm", "rsync-rrsync-0:3.4.1-2.el10_1.2.noarch.rpm", "rsync-0:3.4.1-2.el10_1.2.ppc64le.rpm", "rsync-debugsource-0:3.4.1-2.el10_1.2.ppc64le.rpm", "rsync-0:3.4.1-2.el10_1.2.s390x.rpm", "rsync-0:3.4.1-2.el10_1.2.aarch64.rpm", "rsync-debuginfo-0:3.4.1-2.el10_1.2.x86_64.rpm", "rsync-debuginfo-0:3.4.1-2.el10_1.2.aarch64.rpm","rsync-debugsource-0:3.4.1-2.el10_1.2.s390x.rpm", "rsync-debuginfo-0:3.4.1-2.el10_1.2.ppc64le.rpm", "rsync-debugsource-0:3.4.1-2.el10_1.2.x86_64.rpm", "rsync-debuginfo-0:3.4.1-2.el10_1.2.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rsync security update available for Rocky Linux 10 addressing moderate issues to enhance system protection.. Rsync Security Update, Rocky Linux 10, Array Access, System Protection, Security Advisories. . LinuxSecurity.com Team
Moderate: rsync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6436", "synopsis": "Moderate: rsync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rsync.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.\n\nSecurity Fix(es):\n\n* rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2415637", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2415637", "description": ""}], "cves": [{"name": "CVE-2025-10158", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10158", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-129"}], "references": [], "publishedAt": "2026-04-09T06:02:09.317838Z", "rpms": {"Rocky Linux 8": {"nvras": ["rsync-0:3.1.3-24.el8_10.aarch64.rpm", "rsync-0:3.1.3-24.el8_10.src.rpm", "rsync-0:3.1.3-24.el8_10.x86_64.rpm", "rsync-daemon-0:3.1.3-24.el8_10.noarch.rpm", "rsync-debuginfo-0:3.1.3-24.el8_10.aarch64.rpm", "rsync-debuginfo-0:3.1.3-24.el8_10.x86_64.rpm", "rsync-debugsource-0:3.1.3-24.el8_10.aarch64.rpm", "rsync-debugsource-0:3.1.3-24.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rsync security update for Rocky Linux addresses moderate risks regardingarray access issues and associated threats.. rsync update, Rocky Linux security, rsync utility, security vulnerabilities. . LinuxSecurity.com Team
Moderate: rsync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6390", "synopsis": "Moderate: rsync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rsync.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.\n\nSecurity Fix(es):\n\n* rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2415637", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2415637", "description": ""}], "cves": [{"name": "CVE-2025-10158", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-10158", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-129"}], "references": [], "publishedAt": "2026-04-07T12:03:55.701474Z", "rpms": {"Rocky Linux 9": {"nvras": ["rsync-0:3.2.5-3.el9_7.2.aarch64.rpm", "rsync-0:3.2.5-3.el9_7.2.ppc64le.rpm", "rsync-0:3.2.5-3.el9_7.2.s390x.rpm", "rsync-0:3.2.5-3.el9_7.2.src.rpm", "rsync-0:3.2.5-3.el9_7.2.x86_64.rpm", "rsync-daemon-0:3.2.5-3.el9_7.2.noarch.rpm", "rsync-debuginfo-0:3.2.5-3.el9_7.2.aarch64.rpm", "rsync-debuginfo-0:3.2.5-3.el9_7.2.ppc64le.rpm", "rsync-debuginfo-0:3.2.5-3.el9_7.2.s390x.rpm", "rsync-debuginfo-0:3.2.5-3.el9_7.2.x86_64.rpm", "rsync-debugsource-0:3.2.5-3.el9_7.2.aarch64.rpm","rsync-debugsource-0:3.2.5-3.el9_7.2.ppc64le.rpm", "rsync-debugsource-0:3.2.5-3.el9_7.2.s390x.rpm", "rsync-debugsource-0:3.2.5-3.el9_7.2.x86_64.rpm", "rsync-rrsync-0:3.2.5-3.el9_7.2.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for Rocky Linux addresses moderate rsync security issues and suggests remedial actions for users to take.. Rocky Linux 9 rsync security update,CVE-2025-10158 fix,rsync out-of-bounds access. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for rsync Announcement ID: SUSE-SU-2026:20058-1 Release Date: 2026-01-02T11:13:06Z Rating: moderate References: * bsc#1254441 Cross-References: * CVE-2025-10158 CVSS scores: * CVE-2025-10158 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-10158 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for rsync fixes the following issues: * CVE-2025-10158: Fixed out of bounds array access via negative index (bsc#1254441) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-365=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * rsync-debugsource-3.3.0-slfo.1.1_4.1 * rsync-3.3.0-slfo.1.1_4.1 * rsync-debuginfo-3.3.0-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10158.html * https://bugzilla.suse.com/show_bug.cgi?id=1254441 . SUSE releases a security update for rsync addressing a moderate threat due to out of bounds array access. Update recommended.. SUSE rsync update security patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for rsync Announcement ID: SUSE-SU-2026:0041-1 Release Date: 2026-01-06T10:33:35Z Rating: moderate References: * bsc#1254441 Cross-References: * CVE-2025-10158 CVSS scores: * CVE-2025-10158 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-10158 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for rsync fixes the following issues: * CVE-2025-10158: Fixed out of bounds array access via negative index (bsc#1254441) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-41=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-41=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-41=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-41=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-41=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-41=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 * rsync-3.2.3-150400.3.26.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 *rsync-3.2.3-150400.3.26.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 * rsync-3.2.3-150400.3.26.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 * rsync-3.2.3-150400.3.26.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 * rsync-3.2.3-150400.3.26.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * rsync-debuginfo-3.2.3-150400.3.26.1 * rsync-debugsource-3.2.3-150400.3.26.1 * rsync-3.2.3-150400.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10158.html * https://bugzilla.suse.com/show_bug.cgi?id=1254441 . Update for openSUSE addressing CVE-2025-10158 vulnerability in rsync, rated as moderate; fixes out of bounds access issues.. openSUSE security update, rsync vulnerability, moderate severity patch. . LinuxSecurity.com Team
spice: Off-by-one error in array access in spice/server/memslot.c (CVE-2019-3813) SL7 x86_64 spice-debuginfo-0.14.0-6.el7_6.1.x86_64.rpm spice-server-0.14.0-6.el7_6.1.x86_64.rpm spice-server-devel-0.14.0-6.el7_6.1.x86_64.rpm - Scientific Linux Development Team. Synopsis: Important: spice security update Advisory ID: SLSA-2019:0231-1 Issue Date: 2019-01-31 CVE Numbers: CVE-2019-3813 -- Security Fix(es): * spice: Off-by-one error in array access in spice/server/memslot.c (CVE-2019-3813) -- SL7 x86_64 spice-debuginfo-0.14.0-6.el7_6.1.x86_64.rpm spice-server-0.14.0-6.el7_6.1.x86_64.rpm spice-server-devel-0.14.0-6.el7_6.1.x86_64.rpm - Scientific Linux Development Team . Crucial spice security patch for SL7 responding to an off-by-one flaw in array manipulation. Notification SLSA-2019-0232-2.. spice Security Update, SL7 Important Advisory, Off-by-One Security Issue, Spice Array Access Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.