[CLSA-2026:1777504797] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-04-29 23:20:03 UTC
Description:
- CVE-2024-12086: prevent server from reading arbitrary client files via path traversal - CVE-2025-10158: fix invalid access to files array in sender - Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator - Enable Amazon Linux 2 ELS
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:efb062ff9b9d579a30b6ddb6b91fd8147c7c92695a872c991184a3a12a52edf3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.