rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation.
References
| Link | Resource |
|---|---|
| https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 | Product Release Notes |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-phxh-hjqv-39c9 | Vendor Advisory |
| https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-acl-xattr-application | Release Notes Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 15:19
Updated : 2026-08-31 15:31
NVD link : CVE-2026-53799
Mitre link : CVE-2026-53799
CVE.ORG link : CVE-2026-53799
JSON object : View
Products Affected
samba
- rsync
