Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25172: Important: rsync security update

A use-after-free vulnerability in rsync's extended attribute handling (CVE-2026-41035, CVSS 7.4 HIGH) could allow for potential exploitation. The vulnerability affects rsync versions 3.0.1 through 3.4.1. For Red Hat Enterprise Linux 7 Extended Lifecycle Support, the issue is fixed in the updated package version rsync-3.1.2-12.el7_9.3.
Read Full Article →

Red Hat Product Errata RHSA-2026:25172 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25172 - Security Advisory Overview Updated Packages Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2458898 - CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling CVEs CVE-2026-41035 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM rsync-3.1.2-12.el7_9.3.src.rpm SHA-256: 3570d6c1650cca9df1cc9246cc7da64c1cabf74191ceee9726d20b8cd57ec0f4 x86_64 rsync-3.1.2-12.el7_9.3.x86_64.rpm SHA-256: 86bc58c66c23a617c63aa1c28d180c35ce2b8bbacce473a5f68fad225ea8433a rsync-debuginfo-3.1.2-12.el7_9.3.x86_64.rpm SHA-256: 42311b22b7c49cfb0c6dd4471dd8575591dcf09004aa13b13a811f81b34496ca Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM rsync-3.1.2-12.el7_9.3.src.rpm SHA-256: 3570d6c1650cca9df1cc9246cc7da64c1cabf74191ceee9726d20b8cd57ec0f4 s390x rsync-3.1.2-12.el7_9.3.s390x.rpm SHA-256: bce1d11e25d3ede75200f824f223dee7d78ccef3b2d883790674ea566f2d4b05 rsync-debuginfo-3.1.2-12.el7_9.3.s390x.rpm SHA-256: fac9def428b1e6f706f73c4a11a90be3e96cf44d15bfb8825712a6f6f9ed8396 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM rsync-3.1.2-12.el7_9.3.src.rpm SHA-256: 3570d6c1650cca9df1cc9246cc7da64c1cabf74191ceee9726d20b8cd57ec0f4 ppc64 rsync-3.1.2-12.el7_9.3.ppc64.rpm SHA-256: dd1401f6af46cba6a05e7ff95c16fe7248c0c798ec335072b86658fa2418d4aa rsync-debuginfo-3.1.2-12.el7_9.3.ppc64.rpm SHA-256: 739bc987a4250c2311bae8d84feb48eb91009e766af4b1a06439450d59c39167 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM rsync-3.1.2-12.el7_9.3.src.rpm SHA-256: 3570d6c1650cca9df1cc9246cc7da64c1cabf74191ceee9726d20b8cd57ec0f4 ppc64le rsync-3.1.2-12.el7_9.3.ppc64le.rpm SHA-256: 447600051e4b46dc53b43dba600f5cff20aa7a1b1a96d43dc3b4e25412ed5357 rsync-debuginfo-3.1.2-12.el7_9.3.ppc64le.rpm SHA-256: 5ba921cadb66069bc00476146b7ce153d06457d673005acf14ffc00a76f30d7c The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article