Red Hat Product Errata RHSA-2026:26410 - Security Advisory Issued: 2026-06-16 Updated: 2026-06-16 RHSA-2026:26410 - Security Advisory Overview Updated Packages Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool. Security Fix(es): rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding (CVE-2026-43618) rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. (CVE-2026-29518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2469054 - CVE-2026-43618 rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding BZ - 2469055 - CVE-2026-29518 rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. CVEs CVE-2026-29518 CVE-2026-43618 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca x86_64 rsync-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: 73c95e6404602b407a3cced5f1ae769a2c32b5b4ce9d646fc42617941863082c rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: 036f10ea9159a63c150018966ec0f70dec57501dec22e500e3f9969d8e4e1e64 rsync-debugsource-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: d8614d2fcf96291d37fce432dc38cb77605faf501e3c3168fe1d5c4af8aa9fa0 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca x86_64 rsync-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: 73c95e6404602b407a3cced5f1ae769a2c32b5b4ce9d646fc42617941863082c rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: 036f10ea9159a63c150018966ec0f70dec57501dec22e500e3f9969d8e4e1e64 rsync-debugsource-3.2.5-7.el9_8.2.x86_64.rpm SHA-256: d8614d2fcf96291d37fce432dc38cb77605faf501e3c3168fe1d5c4af8aa9fa0 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for IBM z Systems 9 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca s390x rsync-3.2.5-7.el9_8.2.s390x.rpm SHA-256: d85d04511788214c554ff3068632f9e0edb39c8e7544f0610927f79d76677182 rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.s390x.rpm SHA-256: e57988794b8b5c4641a561ac15b53ea9d9e9ea63c46960fbbc0aeb0b85c1b88a rsync-debugsource-3.2.5-7.el9_8.2.s390x.rpm SHA-256: 8c4987326e6bcceb252cfa7fbf832353c6893b4ac37de9910a01d9c9aeb90542 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca s390x rsync-3.2.5-7.el9_8.2.s390x.rpm SHA-256: d85d04511788214c554ff3068632f9e0edb39c8e7544f0610927f79d76677182 rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.s390x.rpm SHA-256: e57988794b8b5c4641a561ac15b53ea9d9e9ea63c46960fbbc0aeb0b85c1b88a rsync-debugsource-3.2.5-7.el9_8.2.s390x.rpm SHA-256: 8c4987326e6bcceb252cfa7fbf832353c6893b4ac37de9910a01d9c9aeb90542 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for Power, little endian 9 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca ppc64le rsync-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 5e75716946f15a560fffc57967390adfdfc812d6b85997b9d712f041657cfd1f rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 312a775e1875a35439a5b096c83e38989aaf8322213fcbb0dc2a088b43520a78 rsync-debugsource-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 75e26b731ac86fb18653631aec0c2f30d95d7a1bde7eba704f34423c9e880361 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca ppc64le rsync-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 5e75716946f15a560fffc57967390adfdfc812d6b85997b9d712f041657cfd1f rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 312a775e1875a35439a5b096c83e38989aaf8322213fcbb0dc2a088b43520a78 rsync-debugsource-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 75e26b731ac86fb18653631aec0c2f30d95d7a1bde7eba704f34423c9e880361 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for ARM 64 9 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca aarch64 rsync-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 1e1fa89a9a4b843862fb9436295f187c55d314a9eb23d4bb8d6b07b2f41ba067 rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 2980dfe779b6e40a943583877794e6b76f9662fd4d0d1090943389aae66d9bf3 rsync-debugsource-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 8e111baf75171b892de7375632a968d993158e6559186cd5cb6361b01acdc00f rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca aarch64 rsync-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 1e1fa89a9a4b843862fb9436295f187c55d314a9eb23d4bb8d6b07b2f41ba067 rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 2980dfe779b6e40a943583877794e6b76f9662fd4d0d1090943389aae66d9bf3 rsync-debugsource-3.2.5-7.el9_8.2.aarch64.rpm SHA-256: 8e111baf75171b892de7375632a968d993158e6559186cd5cb6361b01acdc00f rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 SRPM rsync-3.2.5-7.el9_8.2.src.rpm SHA-256: 37d0ee99d570df9eadf8244580dc078258ae4c9833ca3458cb6dc5851a7c37ca ppc64le rsync-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 5e75716946f15a560fffc57967390adfdfc812d6b85997b9d712f041657cfd1f rsync-daemon-3.2.5-7.el9_8.2.noarch.rpm SHA-256: fe0b7bff6578f8b1bea4de4ab1e2992f0d6ff276711c08b13525b4a9541f8329 rsync-debuginfo-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 312a775e1875a35439a5b096c83e38989aaf8322213fcbb0dc2a088b43520a78 rsync-debugsource-3.2.5-7.el9_8.2.ppc64le.rpm SHA-256: 75e26b731ac86fb18653631aec0c2f30d95d7a1bde7eba704f34423c9e880361 rsync-rrsync-3.2.5-7.el9_8.2.noarch.rpm SHA-256: 834cea80d7409c68617cd0f4b7ab1519912936ed9bcce72af7eda98bb0d85106 Red Hat Enterprise Linux for x86_64 - Update Ser
This update addresses two Important-severity vulnerabilities in rsync: CVE-2026-43618 (CVSS 8.1 High), a remote memory disclosure via integer overflow in compressed-token decoding, and CVE-2026-29518 (CVSS 7.0 High), a local privilege escalation via a TOCTOU symlink race condition in daemon mode. The vulnerabilities affect rsync versions prior to 3.4.3, and the fix is included in rsync 3.4.3. Red Hat Enterprise Linux 9 users should apply the provided security update.