[CLSA-2026:1780945931] rsync: Fix of CVE-2026-43617
Type:
security
Severity:
Moderate
Release date:
2026-06-08 19:12:27 UTC
Description:
- CVE-2026-43617: fix hostname ACL bypass when using daemon chroot by performing the reverse-DNS lookup before entering the chroot so client_name() caches a usable hostname and "hosts deny" rules match
CVEs fixed:
Updated packages:
  • rsync-3.2.3-19.el9_2.tuxcare.els10.x86_64.rpm
    sha:aca18f913dd8e55d339e141e30283a7ee3ddaa40898c04b6f5f3586a1effe7f9
  • rsync-daemon-3.2.3-19.el9_2.tuxcare.els10.noarch.rpm
    sha:d101e90cd99bea65813a55a7ae3b3d224b72054749a6e54ba38e6a32f0e12af6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.