[CLSA-2026:1777544655] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-02 01:10:44 UTC
Description:
- CVE-2024-12086: prevent server from reading arbitrary client files via path traversal - CVE-2025-10158: fix invalid access to files array in sender - Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator - Enable Amazon Linux 2 ELS
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:0dbe2f87d74efb5f4853140bed9af49fa483d1b0199d660cbd34bbda423ba827
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.