Symlink Race Condition Vulnerability in rsync Affected by Local Attackers
CVE-2026-53799

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-53799?

The vulnerability in rsync allows local attackers to exploit a symlink race condition, enabling them to apply arbitrary Access Control Lists (ACLs) or extended attributes to unintended files. This occurs by substituting a symlink during the window between the file writing process and the ACL or extended attribute assignment, potentially leading to unauthorized changes in file permissions. This flaw can permit elevated privileges, allowing attackers to manipulate system files outside the specified directory tree, posing a significant security risk.

Affected Version(s)

rsync 0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gregkh
.