ELSA-2026-26408

ELSA-2026-26408 - rsync security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-06-16

Description


[3.1.3-27]
- Integer overflow in compressed-token decoding (CVE-2026-43618)
- Resolves: RHEL-174951

[3.1.3-26]
- Resolves: RHEL-174950 - CVE-2026-29518 - TOCTOU symlink race in
non-chrooted daemon modules


Related CVEs


CVE-2026-29518
CVE-2026-43618

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) rsync-3.1.3-27.el8_10.src.rpme9037aff509a984d3b8f75410f815252b93368c035d708cb94482b8e38438598-ol8_aarch64_baseos_latest
rsync-3.1.3-27.el8_10.src.rpme9037aff509a984d3b8f75410f815252b93368c035d708cb94482b8e38438598-ol8_aarch64_u10_baseos_patch
rsync-3.1.3-27.el8_10.aarch64.rpm80d64ad559b26e52e2c477c3ac1044fea37011abdd52200204f2fb08b96bc83f-ol8_aarch64_baseos_latest
rsync-3.1.3-27.el8_10.aarch64.rpm80d64ad559b26e52e2c477c3ac1044fea37011abdd52200204f2fb08b96bc83f-ol8_aarch64_u10_baseos_patch
rsync-daemon-3.1.3-27.el8_10.noarch.rpm0e8be7664059bc6919f331a380c32154ab4b59a5f07593ffc6085e71bd2ca1eb-ol8_aarch64_baseos_latest
rsync-daemon-3.1.3-27.el8_10.noarch.rpm0e8be7664059bc6919f331a380c32154ab4b59a5f07593ffc6085e71bd2ca1eb-ol8_aarch64_u10_baseos_patch
Oracle Linux 8 (x86_64) rsync-3.1.3-27.el8_10.src.rpme9037aff509a984d3b8f75410f815252b93368c035d708cb94482b8e38438598-ol8_x86_64_baseos_latest
rsync-3.1.3-27.el8_10.src.rpme9037aff509a984d3b8f75410f815252b93368c035d708cb94482b8e38438598-ol8_x86_64_u10_baseos_patch
rsync-3.1.3-27.el8_10.x86_64.rpm6a7214afad0c6bdc50f5f3b7f306d0218a8d43b3af902ec3ac8de380994916fe-ol8_x86_64_baseos_latest
rsync-3.1.3-27.el8_10.x86_64.rpm6a7214afad0c6bdc50f5f3b7f306d0218a8d43b3af902ec3ac8de380994916fe-ol8_x86_64_u10_baseos_patch
rsync-daemon-3.1.3-27.el8_10.noarch.rpm0e8be7664059bc6919f331a380c32154ab4b59a5f07593ffc6085e71bd2ca1eb-ol8_x86_64_baseos_latest
rsync-daemon-3.1.3-27.el8_10.noarch.rpm0e8be7664059bc6919f331a380c32154ab4b59a5f07593ffc6085e71bd2ca1eb-ol8_x86_64_u10_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete