Home / mailings [SECURITY] [DSA 6527-1] rsync security update
Posted on 28 September 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6527-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
September 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : rsync
CVE ID : CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786
CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791
CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795
CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799
CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803
CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455
CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459
CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463
CVE-2026-70464
Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool, which could result in local
privilege escalation, bypass of intended access restrictions,
information disclosure, denial of service or the execution of arbitrary
code.
Details can be found at
https://download.samba.org/pub/rsync/NEWS#3.5.0
For the stable distribution (trixie), these problems have been fixed in
version 3.5.0+ds1-0+deb13u1.
We recommend that you upgrade your rsync packages.
For the detailed security status of rsync please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/rsync
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
