红帽产品勘误 RHSA-2026:25170 - Security Advisory 发布: 2026-06-11 已更新: 2026-06-11 RHSA-2026:25170 - Security Advisory 概述 更新的软件包 概述 Important: rsync security update 类型/严重性 Security Advisory: Important Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update for rsync is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 描述 The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): rsync: Rsync: Use-after-free vulnerability in extended attribute handling (CVE-2026-41035) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 解决方案 For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 受影响的产品 Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 修复 BZ - 2458898 - CVE-2026-41035 rsync: Rsync: Use-after-free vulnerability in extended attribute handling CVE CVE-2026-41035 参考 https://access.redhat.com/security/updates/classification/#important 备注: 可能有这些软件包的更新版本。 点击软件包名称查看详情。 Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM rsync-3.1.3-12.el8_4.7.src.rpm SHA-256: 11fbec758496cf395f12881475df42cfc98faf2d055cc54fbfd6cd0381ad725e x86_64 rsync-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: 646dd6cbf4adb2e88c5b125c1f7d48bf708738aeae1e8303e892ee34e4a31780 rsync-daemon-3.1.3-12.el8_4.7.noarch.rpm SHA-256: 8b0ce94022c1142bbd2b1b3973b8fde109df04b858c9215168cf282ef6d3c88d rsync-debuginfo-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: 8c89992092458491823673d85c4e90b1ea7daf41855e421d44f8472b85e38d04 rsync-debugsource-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: cbab98f0241e64798176332d4d7312b76ccd04d8c26909f5b0ecc333cd97a5ef Red Hat Enterprise Linux Server - AUS 8.4 SRPM rsync-3.1.3-12.el8_4.7.src.rpm SHA-256: 11fbec758496cf395f12881475df42cfc98faf2d055cc54fbfd6cd0381ad725e x86_64 rsync-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: 646dd6cbf4adb2e88c5b125c1f7d48bf708738aeae1e8303e892ee34e4a31780 rsync-daemon-3.1.3-12.el8_4.7.noarch.rpm SHA-256: 8b0ce94022c1142bbd2b1b3973b8fde109df04b858c9215168cf282ef6d3c88d rsync-debuginfo-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: 8c89992092458491823673d85c4e90b1ea7daf41855e421d44f8472b85e38d04 rsync-debugsource-3.1.3-12.el8_4.7.x86_64.rpm SHA-256: cbab98f0241e64798176332d4d7312b76ccd04d8c26909f5b0ecc333cd97a5ef Red Hat 安全团队联络方式为 secalert@redhat.com 。 更多联络细节请参考 https://access.redhat.com/security/team/contact/ 。
A use-after-free vulnerability (CVE-2026-41035, CVSS 7.4 High) in rsync's extended attribute handling could allow an attacker to execute arbitrary code or cause a denial of service. The NVD data indicates rsync versions from 3.0.1 through 3.4.1 are affected. The Red Hat advisory provides patched packages (e.g., rsync-3.1.3-12.el8_4.7) for specific RHEL 8.4 support channels.