Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended attributes to unintended files by substituting a symlink at a predictable destination path between the file write and the subsequent acl_set_file() or lsetxattr() call. Attackers can exploit this timing window to redirect ACL and xattr application through a crafted symlink to files outside the intended destination tree, potentially granting elevated permissions and enabling local privilege escalation. | |
| Title | rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application | |
| Weaknesses | CWE-367 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:40:45.664Z
Reserved: 2026-06-10T20:14:32.828Z
Link: CVE-2026-53799
No data.
Status : Received
Published: 2026-08-13T15:19:52.130
Modified: 2026-08-13T15:19:52.130
Link: CVE-2026-53799
No data.
OpenCVE Enrichment
No data.