[CLSA-2026:1777476699] rsync: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-29 15:31:44 UTC
Description:
- CVE-2017-16548: enforce trailing NUL on received xattr names in receive_xattr() - CVE-2017-17434: sanitize xname strings in read_ndx_and_attrs() and check fnamecmp against the daemon filter list
Updated packages:
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els4.x86_64.rpm
    sha:f5aa87d09fac95b163bce16935dd9ec60c4256e7d5ff6840e5cc020c646e2dc6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.