ELSA-2026-26410

ELSA-2026-26410 - rsync security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-06-23

Description


[3.2.5-7.2]
- Fix integer overflow in compressed-token decoding (CVE-2026-43618)
- Resolves: RHEL-174932

[3.2.5-7.1]
- Fix TOCTOU symlink race in daemon no-chroot mode (CVE-2026-29518)
- Resolves: RHEL-174952

[3.2.5-4]
- Resolves: RHEL-104404 - Do not clear DISPLAY unconditionally


Related CVEs


CVE-2026-29518
CVE-2026-43618

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_aarch64_appstream
rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_aarch64_baseos_latest
rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_aarch64_u8_baseos_patch
rsync-3.2.5-7.el9_8.2.aarch64.rpmd53a480c23680ac3921dddca6ca7ee2446cd83f0cbf5676f943764dee459f03f-ol9_aarch64_baseos_latest
rsync-3.2.5-7.el9_8.2.aarch64.rpmd53a480c23680ac3921dddca6ca7ee2446cd83f0cbf5676f943764dee459f03f-ol9_aarch64_u8_baseos_patch
rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm34ec41f800a8b6ca04e7b029fa473f184512d502f1564e901ab0adada43e1e40-ol9_aarch64_appstream
rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpme91ec2b7f04bcfa44a55f7c41599dd102ee7ea9f4aee81d3b31cb99350eb7d00-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_x86_64_appstream
rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_x86_64_baseos_latest
rsync-3.2.5-7.el9_8.2.src.rpmd65970ba79a89e3ea2da4c4e7bbc4d9778340ab0de59f1fe94c8d2df12b5bf21-ol9_x86_64_u8_baseos_patch
rsync-3.2.5-7.el9_8.2.x86_64.rpmb8564677a73672d55bb66229d164e9fde8bb6802720e50d2ab2410f5b2be88b3-ol9_x86_64_baseos_latest
rsync-3.2.5-7.el9_8.2.x86_64.rpmb8564677a73672d55bb66229d164e9fde8bb6802720e50d2ab2410f5b2be88b3-ol9_x86_64_u8_baseos_patch
rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm34ec41f800a8b6ca04e7b029fa473f184512d502f1564e901ab0adada43e1e40-ol9_x86_64_appstream
rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpme91ec2b7f04bcfa44a55f7c41599dd102ee7ea9f4aee81d3b31cb99350eb7d00-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete