[CLSA-2026:1777469554] rsync: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-04-29 13:32:39 UTC
Description:
- CVE-2024-12086: prevent server from reading arbitrary client files via path traversal - CVE-2025-10158: fix invalid access to files array in sender - Add upstream stability fix (RsyncProject/rsync PR #706): use-after-free in generator - Enable Amazon Linux 2 ELS
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:1ca3d098f1f2ed42e5d06fa5d615ec41b68ab0cc7c8900c65b7b62a386c57c13
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.