{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2026/cve-2026-53783-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-27T16:40:09Z",
      "generator": {
        "date": "2026-08-27T16:40:09Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-53783-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2026-08-13T15:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-13T15:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-16T14:47:43Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-27T16:40:09Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-53783"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6.amd64",
                  "product_id": "rsync-0:3.1.3-6.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.1.3-6?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53783",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64",
          "Debian-10:rsync-0:3.1.3-6.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53783"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync",
          "url": "https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-27T14:52:46.292672Z",
          "details": "We are not fixing this on this platform because the affected helper script is shipped as documentation only: it is installed without execute permission and is not on the command path, so an administrator must deliberately copy it out and make it executable before any exposure exists. The fix is also not portable here — the later upstream version rewrites that script in a different language, using facilities this version's script does not have, so it would have to be written from scratch rather than backported. Where someone has deployed the script, an attacker can escape its restricted directory by racing the path it checks. To stay safe, do not deploy the shipped script; restrict keys with a purpose-built wrapper, or use a daemon module with chroot enabled.",
          "product_ids": [
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64",
            "Debian-10:rsync-0:3.1.3-6.amd64"
          ]
        }
      ]
    }
  ]
}