rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.
References
| Link | Resource |
|---|---|
| https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 | Product Release Notes |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-v3vw-pvpg-chwh | Vendor Advisory |
| https://www.vulncheck.com/advisories/rsync-symlink-race-condition-via-remove-source-files | Release Notes Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 15:19
Updated : 2026-08-31 15:31
NVD link : CVE-2026-53800
Mitre link : CVE-2026-53800
CVE.ORG link : CVE-2026-53800
JSON object : View
Products Affected
samba
- rsync
