rsync 3.5.0 security update — distribution status

Which distributions have shipped rsync 3.5.0 or backports of the 33 CVEs it fixes (release notes). rsync 3.5.0 was released on 13 August 2026; generated 2026-10-04 17:25 UTC, 52 days after release.

Overview

DistributionReleasersync versionStatus
FedoraFedora 46 (rawhide)3.5.1-1.fc46Fixed
Fedora 45 (branched)3.5.0-2.fc45Fixed
Fedora 443.5.1-1.fc44Fixed
Fedora 433.5.0-2.fc43Fixed
Fedora 423.4.1-5.fc42End of life
Fedora ELN3.5.1-1.eln159Fixed
Debiansid (unstable)3.5.1+ds1-1Fixed
forky (Debian 14, testing)3.5.1+ds1-1Fixed
trixie (Debian 13, stable)3.4.1+ds1-5+deb13u4 (security: 3.5.0+ds1-0+deb13u1)Fixed
bookworm (Debian 12, oldstable)3.2.7-1+deb12u6 (security: 3.2.7-1+deb12u5)Vulnerable
bullseye (Debian 11, LTS)3.2.3-4+deb11u1 (security: 3.2.3-4+deb11u4)Unknown
Ubuntu26.10 'stonking' (devel)3.5.0+ds1-2Fixed
26.04 LTS 'resolute'3.4.1+ds1-7ubuntu0.3Vulnerable
25.10 'questing'3.4.1+ds1-5ubuntu1.3End of life
24.04 LTS 'noble'3.2.7-1ubuntu1.5Vulnerable
22.04 LTS 'jammy'3.2.7-0ubuntu0.22.04.7Vulnerable
20.04 'focal' (ESM)3.1.3-8ubuntu0.9Vulnerable
Red Hat Enterprise LinuxRHEL 10Partially fixed
RHEL 9Partially fixed
RHEL 8Partially fixed
RHEL 7 (ELS)Vulnerable
RHEL 6 (ELS)Vulnerable
SUSE / openSUSEopenSUSE Leap 16.0Fixed
SLES 15 SP7Fixed
SLES 15 SP6 LTSSFixed
SLES 12 SP5 LTSSVulnerable
SUSE Linux Micro 6.2Fixed
Alpineedge (rolling)3.5.1-r0Fixed
3.24 (stable)3.5.0-r0Fixed
3.233.5.0-r0Fixed
3.223.5.0-r0Fixed
3.213.5.0-r0Fixed
Arch LinuxArch (rolling)3.5.1-1Fixed
GentooGentoo (stable, amd64)3.5.1Fixed
Gentoo (~amd64 testing)3.5.0Fixed
Other repositoriesopenSUSE Tumbleweed3.5.1Fixed
NixOS (unstable)3.5.0Fixed
NixOS 25.113.4.13.5.0 not shipped
NixOS 25.053.4.13.5.0 not shipped
FreeBSD ports3.5.1Fixed
OpenBSD ports3.5.0Fixed
NetBSD pkgsrc3.5.1Fixed
Homebrew3.5.1Fixed
MacPorts3.5.0Fixed
Void Linux3.5.1Fixed
Slackware current3.5.1Fixed
GNU Guix3.5.0Fixed
OpenWrt 24.103.5.1Fixed

Fixed all 33 CVEs addressed   Partially fixed some CVEs still open   Fix in progress fix queued/testing   Vulnerable no fixes shipped   3.5.0 not shipped pre-3.5.0, backports not visible   End of life unsupported

Fedora

Releasersync versionStatusCVE coverage (of 33)
Fedora 46 (rawhide) 3.5.1-1.fc46 Fixed 33 fixed update FEDORA-2026-58041d072d stable 2026-10-02 21:58:21
Fedora 45 (branched) 3.5.0-2.fc45 Fixed 33 fixed update FEDORA-2026-a5a7d496f8 stable 2026-09-12 00:17:56
Fedora 44 3.5.1-1.fc44 Fixed 33 fixed update FEDORA-2026-1611964b12 stable 2026-10-04 01:41:01
Fedora 43 3.5.0-2.fc43 Fixed 33 fixed update FEDORA-2026-8ebf4eccd6 stable 2026-09-11 01:26:24
Fedora 42 3.4.1-5.fc42 End of life 33 open end of life; no further updates
Fedora ELN 3.5.1-1.eln159 Fixed 33 fixed update FEDORA-2026-f603f14d70 stable 2026-10-03 01:04:23

Fedora ships full 3.5.0 rebases (no patch backports needed).

Per-CVE breakdown
CVEFedora 46 (rawhide)Fedora 45 (branched)Fedora 44Fedora 43Fedora 42Fedora ELN
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedfixedfixedfixedopenfixed
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMfixedfixedfixedfixedopenfixed
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedfixedfixedfixedopenfixed
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedfixedfixedfixedopenfixed

Data: bodhi.fedoraproject.org (fetched 2026-10-04T17:23:42Z)

Debian

Releasersync versionStatusCVE coverage (of 33)
sid (unstable) 3.5.1+ds1-1 Fixed 33 fixed
forky (Debian 14, testing) 3.5.1+ds1-1 Fixed 33 fixed
trixie (Debian 13, stable) 3.4.1+ds1-5+deb13u4 (security: 3.5.0+ds1-0+deb13u1) Fixed 33 fixed
bookworm (Debian 12, oldstable) 3.2.7-1+deb12u6 (security: 3.2.7-1+deb12u5) Vulnerable 33 open
bullseye (Debian 11, LTS) 3.2.3-4+deb11u1 (security: 3.2.3-4+deb11u4) Unknown 33 unknown
Per-CVE breakdown
CVEsid (unstable)forky (Debian 14, testing)trixie (Debian 13, stable)bookworm (Debian 12, oldstable)bullseye (Debian 11, LTS)
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedfixedfixedopen?
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedfixedfixedopen?
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedfixedfixedopen?
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMfixedfixedfixedopen?
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMfixedfixedfixedopen?
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedfixedfixedopen?
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedfixedfixedopen?
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedfixedfixedopen?
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMfixedfixedfixedopen?
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedfixedfixedopen?
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMfixedfixedfixedopen?
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedfixedfixedopen?
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMfixedfixedfixedopen?
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMfixedfixedfixedopen?
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMfixedfixedfixedopen?
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMfixedfixedfixedopen?
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMfixedfixedfixedopen?
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMfixedfixedfixedopen?
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedfixedfixedopen?
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedfixedfixedopen?
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedfixedfixedopen?
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedfixedfixedopen?
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedfixedfixedopen?
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedfixedfixedopen?
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedfixedfixedopen?
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedfixedfixedopen?
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedfixedfixedopen?
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMfixedfixedfixedopen?
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedfixedfixedopen?
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedfixedfixedopen?
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMfixedfixedfixedopen?
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedfixedfixedopen?
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedfixedfixedopen?

Data: security-tracker.debian.org, qa.debian.org (fetched 2026-10-04T17:23:44Z)

Ubuntu

Releasersync versionStatusCVE coverage (of 33)
26.10 'stonking' (devel) 3.5.0+ds1-2 Fixed 33 fixed
26.04 LTS 'resolute' 3.4.1+ds1-7ubuntu0.3 Vulnerable 33 open
25.10 'questing' 3.4.1+ds1-5ubuntu1.3 End of life 33 open end of life; no further updates
24.04 LTS 'noble' 3.2.7-1ubuntu1.5 Vulnerable 33 open
22.04 LTS 'jammy' 3.2.7-0ubuntu0.22.04.7 Vulnerable 33 open
20.04 'focal' (ESM) 3.1.3-8ubuntu0.9 Vulnerable 33 open

Status from the ubuntu-cve-tracker; 'open' includes needs-triage.

Per-CVE breakdown
CVE26.10 'stonking' (devel)26.04 LTS 'resolute'25.10 'questing'24.04 LTS 'noble'22.04 LTS 'jammy'20.04 'focal' (ESM)
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedopenopenopenopenopen
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedopenopenopenopenopen
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedopenopenopenopenopen
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMfixedopenopenopenopenopen
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMfixedopenopenopenopenopen
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedopenopenopenopenopen
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedopenopenopenopenopen
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedopenopenopenopenopen
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMfixedopenopenopenopenopen
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedopenopenopenopenopen
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMfixedopenopenopenopenopen
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedopenopenopenopenopen
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMfixedopenopenopenopenopen
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMfixedopenopenopenopenopen
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMfixedopenopenopenopenopen
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMfixedopenopenopenopenopen
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMfixedopenopenopenopenopen
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMfixedopenopenopenopenopen
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedopenopenopenopenopen
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedopenopenopenopenopen
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedopenopenopenopenopen
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedopenopenopenopenopen
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedopenopenopenopenopen
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedopenopenopenopenopen
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedopenopenopenopenopen
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedopenopenopenopenopen
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedopenopenopenopenopen
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMfixedopenopenopenopenopen
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedopenopenopenopenopen
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedopenopenopenopenopen
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMfixedopenopenopenopenopen
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedopenopenopenopenopen
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedopenopenopenopenopen

Data: git.launchpad.net, launchpad.net (fetched 2026-10-04T17:24:20Z)

Red Hat Enterprise Linux

Releasersync versionStatusCVE coverage (of 33)
RHEL 10 Partially fixed 21 fixed, 12 open
RHEL 9 Partially fixed 20 fixed, 12 open, 1 n/a
RHEL 8 Partially fixed 17 fixed, 9 open, 7 n/a
RHEL 7 (ELS) Vulnerable 19 open, 7 n/a, 7 won't fix
RHEL 6 (ELS) Vulnerable 15 open, 11 n/a, 7 won't fix

Red Hat backports fixes; status is per-CVE from the Red Hat security data API. CentOS Stream generally follows RHEL.

Per-CVE breakdown
CVERHEL 10RHEL 9RHEL 8RHEL 7 (ELS)RHEL 6 (ELS)
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedfixedfixedopenopen
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedfixedfixedopenopen
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedfixedfixedopenopen
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMopenopenn/an/an/a
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedfixedfixedopenopen
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedfixedfixedopenopen
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedfixedn/an/an/a
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMopenopenopenopenopen
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedfixedfixedopenopen
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMopenopenn/an/an/a
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedfixedfixedopenopen
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMopenopenn/an/an/a
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedfixedfixedopenopen
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedfixedfixedopenopen
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedfixedfixedopenn/a
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedfixedfixedopenopen
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedfixedn/an/an/a
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedn/an/an/an/a
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedfixedfixedopenopen
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedfixedn/an/an/a
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedfixedfixedopenopen
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMopenopenopenwon't fixwon't fix
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedfixedfixedopenopen
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedfixedfixedopenn/a
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMopenopenopenopenn/a
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedfixedfixedopenn/a
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedfixedfixedopenopen

Data: access.redhat.com, access.redhat.com (fetched 2026-10-04T17:23:37Z)

SUSE / openSUSE

Releasersync versionStatusCVE coverage (of 33)
openSUSE Leap 16.0 Fixed 33 fixed
SLES 15 SP7 Fixed 33 fixed
SLES 15 SP6 LTSS Fixed 33 fixed
SLES 12 SP5 LTSS Vulnerable 30 open, 3 n/a
SUSE Linux Micro 6.2 Fixed 33 fixed

SUSE backports fixes; status is from SUSE CSAF-VEX documents (a 'recommended' product entry names the released fix version). openSUSE Tumbleweed is not in the CSAF feed; see Other repositories for its version.

Per-CVE breakdown
CVEopenSUSE Leap 16.0SLES 15 SP7SLES 15 SP6 LTSSSLES 12 SP5 LTSSSUSE Linux Micro 6.2
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedfixedfixedopenfixed
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedfixedfixedopenfixed
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedfixedfixedopenfixed
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedfixedfixedopenfixed
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedfixedfixedopenfixed
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedfixedfixedopenfixed
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedfixedfixedopenfixed
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMfixedfixedfixedopenfixed
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedfixedfixedopenfixed
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedfixedfixedopenfixed
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedfixedfixedopenfixed
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedfixedfixedopenfixed
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedfixedfixedopenfixed
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedfixedfixedn/afixed
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedfixedfixedopenfixed
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedfixedfixedn/afixed
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedfixedfixedopenfixed
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMfixedfixedfixedopenfixed
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedfixedfixedopenfixed
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedfixedfixedn/afixed
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMfixedfixedfixedopenfixed
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedfixedfixedopenfixed
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedfixedfixedopenfixed

Data: ftp.suse.com, www.suse.com (fetched 2026-10-04T17:25:23Z)

Alpine

Releasersync versionStatusCVE coverage (of 33)
edge (rolling) 3.5.1-r0 Fixed 33 fixed
3.24 (stable) 3.5.0-r0 Fixed 33 fixed
3.23 3.5.0-r0 Fixed 33 fixed
3.22 3.5.0-r0 Fixed 33 fixed
3.21 3.5.0-r0 Fixed 33 fixed

Fixed-CVE data from Alpine's secdb secfixes records.

Data: secdb.alpinelinux.org, gitlab.alpinelinux.org (fetched 2026-10-04T17:24:02Z)

Arch Linux

Releasersync versionStatusCVE coverage (of 33)
Arch (rolling) 3.5.1-1 Fixed 33 fixed 3.5.0 in [extra] since 2026-09-21

Data: archlinux.org, security.archlinux.org (fetched 2026-10-04T17:23:48Z)

Gentoo

Releasersync versionStatusCVE coverage (of 33)
Gentoo (stable, amd64) 3.5.1 Fixed 33 fixed
Gentoo (~amd64 testing) 3.5.0 Fixed 33 fixed

Stabilization is tracked per-arch; check for a GLSA once stable.

Data: packages.gentoo.org (fetched 2026-10-04T17:23:50Z)

Other repositories

Releasersync versionStatusCVE coverage (of 33)
openSUSE Tumbleweed 3.5.1 Fixed 33 fixed
NixOS (unstable) 3.5.0 Fixed 33 fixed
NixOS 25.11 3.4.1 3.5.0 not shipped 33 unknown backport status not visible
NixOS 25.05 3.4.1 3.5.0 not shipped 33 unknown backport status not visible
FreeBSD ports 3.5.1 Fixed 33 fixed
OpenBSD ports 3.5.0 Fixed 33 fixed
NetBSD pkgsrc 3.5.1 Fixed 33 fixed
Homebrew 3.5.1 Fixed 33 fixed
MacPorts 3.5.0 Fixed 33 fixed
Void Linux 3.5.1 Fixed 33 fixed
Slackware current 3.5.1 Fixed 33 fixed
GNU Guix 3.5.0 Fixed 33 fixed
OpenWrt 24.10 3.5.1 Fixed 33 fixed

Version-only data from Repology; a repo shown as vulnerable may still carry unadvertised backports.

Per-CVE breakdown
CVEopenSUSE TumbleweedNixOS (unstable)NixOS 25.11NixOS 25.05FreeBSD portsOpenBSD portsNetBSD pkgsrcHomebrewMacPortsVoid LinuxSlackware currentGNU GuixOpenWrt 24.10
CVE-2026-53783
rrsync restricted-directory escape
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53784
Daemon module-root chdir symlink escape with 'use chroot = no'
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53785
Receiver --relative implied-parent symlink traversal
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53786
Client --filter merge file bypasses daemon module filters
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53788
Newline injection into daemon name-converter protocol
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53789
Malicious daemon-sender widens --delete scope
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53790
Command/argument injection via unquoted host values
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53791
PROXY protocol header spoofing bypasses host access control
CRITICALfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53792
Sender out-of-bounds reads from zero block-length checksum header
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53793
Chroot '/./' inner-module symlink escape
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53794
--max-alloc=0 disables allocation cap, forwardable on the wire
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53795
Absolute --temp-dir/--link-dest disable receiver confinement
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53796
Non-daemon receiver destination chdir not fully confined
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53797
Sender source-file open follows parent-component symlinks
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53798
Daemon name converter maps unknown names to uid/gid 0
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53799
Receiver ACL/xattr symlink race: local privilege escalation
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53800
--remove-source-files parent symlink race: arbitrary deletion
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53801
Directory-scan enumeration escapes transfer root
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53802
Arbitrary file read via symlinked operator-supplied input files
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-53803
Arbitrary file write / LPE via symlinked operator output paths
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70452
'hosts deny' fails open on DNS resolution failure
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70453
Quadratic CPU exhaustion in hash_search (DoS)
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70454
rsync-ssl accepts unauthenticated TLS connections
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70455
Daemon client-controlled Zstandard worker count (memory DoS)
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70456
Heap out-of-bounds write in read_args at maxargs boundary
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70457
Attacker-offset write in parse_size_arg error formatting
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70458
Out-of-bounds write via FLAG_HLINKED entry without -H
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70459
Wild-pointer read crash from crafted incremental file list
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70460
Peer-supplied --partial-dir/--backup-dir symlink redirect
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70461
One-byte heap out-of-bounds write in add_implied_include
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70462
Peer MSG_IO_TIMEOUT overflow defeats client I/O timeout
MEDIUMfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70463
'auth users' comma-parsing authorization bypass
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed
CVE-2026-70464
Unauthenticated daemon connection stall (slowloris DoS)
HIGHfixedfixed??fixedfixedfixedfixedfixedfixedfixedfixedfixed

Data: repology.org (fetched 2026-10-04T17:23:51Z)

The 33 CVEs fixed in rsync 3.5.0

CVESeveritySummary
CVE-2026-53783HIGHrrsync restricted-directory escape
CVE-2026-53784HIGHDaemon module-root chdir symlink escape with 'use chroot = no'
CVE-2026-53785HIGHReceiver --relative implied-parent symlink traversal
CVE-2026-53786MEDIUMClient --filter merge file bypasses daemon module filters
CVE-2026-53788MEDIUMNewline injection into daemon name-converter protocol
CVE-2026-53789MEDIUMMalicious daemon-sender widens --delete scope
CVE-2026-53790HIGHCommand/argument injection via unquoted host values
CVE-2026-53791CRITICALPROXY protocol header spoofing bypasses host access control
CVE-2026-53792MEDIUMSender out-of-bounds reads from zero block-length checksum header
CVE-2026-53793HIGHChroot '/./' inner-module symlink escape
CVE-2026-53794MEDIUM--max-alloc=0 disables allocation cap, forwardable on the wire
CVE-2026-53795HIGHAbsolute --temp-dir/--link-dest disable receiver confinement
CVE-2026-53796MEDIUMNon-daemon receiver destination chdir not fully confined
CVE-2026-53797MEDIUMSender source-file open follows parent-component symlinks
CVE-2026-53798MEDIUMDaemon name converter maps unknown names to uid/gid 0
CVE-2026-53799MEDIUMReceiver ACL/xattr symlink race: local privilege escalation
CVE-2026-53800MEDIUM--remove-source-files parent symlink race: arbitrary deletion
CVE-2026-53801MEDIUMDirectory-scan enumeration escapes transfer root
CVE-2026-53802HIGHArbitrary file read via symlinked operator-supplied input files
CVE-2026-53803HIGHArbitrary file write / LPE via symlinked operator output paths
CVE-2026-70452HIGH'hosts deny' fails open on DNS resolution failure
CVE-2026-70453HIGHQuadratic CPU exhaustion in hash_search (DoS)
CVE-2026-70454MEDIUMrsync-ssl accepts unauthenticated TLS connections
CVE-2026-70455HIGHDaemon client-controlled Zstandard worker count (memory DoS)
CVE-2026-70456HIGHHeap out-of-bounds write in read_args at maxargs boundary
CVE-2026-70457MEDIUMAttacker-offset write in parse_size_arg error formatting
CVE-2026-70458HIGHOut-of-bounds write via FLAG_HLINKED entry without -H
CVE-2026-70459MEDIUMWild-pointer read crash from crafted incremental file list
CVE-2026-70460HIGHPeer-supplied --partial-dir/--backup-dir symlink redirect
CVE-2026-70461HIGHOne-byte heap out-of-bounds write in add_implied_include
CVE-2026-70462MEDIUMPeer MSG_IO_TIMEOUT overflow defeats client I/O timeout
CVE-2026-70463HIGH'auth users' comma-parsing authorization bypass
CVE-2026-70464HIGHUnauthenticated daemon connection stall (slowloris DoS)

Full details in the rsync 3.5.0 release notes.