[CLSA-2026:1777474126] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-04-29 14:48:51 UTC
Description:
- CVE-2024-12086: prevent server from reading arbitrary client files via path traversal - CVE-2025-10158: fix invalid access to files array in sender - Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator - Enable Amazon Linux 2 ELS
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:f412dd63d0817a570cb612d3b78a5a7a0496b3fa737b98d3cbff66cc0ca94bb6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.