security advisorydenial of servicedebian
Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool, which may result in local privilege escalation, bypass of intended access restrictions, remote memory disclosure to an authenticated daemon peer or denial of service. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4591-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz May 20, 2026 https://wiki.debian.org/LTS Package : rsync Version : 3.2.3-4+deb11u4 CVE ID : CVE-2026-29518 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool, which may result in local privilege escalation, bypass of intended access restrictions, remote memory disclosure to an authenticated daemon peer or denial of service. For Debian 11 bullseye, these problems have been fixed in version 3.2.3-4+deb11u4. We recommend that you upgrade your rsync packages. For the detailed security status of rsync please refer to its security tracker page at: https://security-tracker.debian.org/tracker/rsync Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Local privilege escalation and remote memory disclosure were fixed in rsync version 3.2.3-4+deb11u4 for Debian 11.. Debian LTS, rsync vulnerabilities, security update, local privilege escalation, remote disclosure. . Severity: Critical. LinuxSecurity.com Team
May 20, 2026
•Critical
Debian LTS