Rsync File-Copying Tool Vulnerability in Chroot Configurations by Rsync
CVE-2026-44507
4.8MEDIUM
What is CVE-2026-44507?
Rsync, a popular tool for file synchronization, has a vulnerability in its daemon configuration when utilized within a chroot environment. If the chroot setup does not include necessary resolution files, such as /etc/resolv.conf or /etc/hosts, the system fails to resolve the hostname of connecting clients properly. This can lead to situations where hostname-based access restrictions are ineffective, allowing unauthorized connections from potentially malicious users who control their PTR records. This issue, present in versions released before 3.4.3, has been addressed and resolved in the latest update.
Affected Version(s)
rsync < 3.4.3
