[CLSA-2026:1777471422] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-04-29 14:03:46 UTC
Description:
- CVE-2024-12086: prevent server from reading arbitrary client files via path traversal - CVE-2025-10158: fix invalid access to files array in sender - Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator - Enable Amazon Linux 2 ELS
Updated packages:
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els3.x86_64.rpm
    sha:62ecdf7d6c39c808d3cef4c9641846d6283e36868d7e4ff04ede64f7a4f83519
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.