{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2026/cve-2026-53785-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-27T16:40:09Z",
      "generator": {
        "date": "2026-08-27T16:40:09Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-53785-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2026-08-13T15:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-13T15:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-16T14:47:42Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-27T16:40:09Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-53785"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6.amd64",
                  "product_id": "rsync-0:3.1.3-6.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.1.3-6?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                  "product_id": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-6%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els4.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els3.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-6.amd64 as a component of Debian 10",
          "product_id": "Debian-10:rsync-0:3.1.3-6.amd64"
        },
        "product_reference": "rsync-0:3.1.3-6.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53785",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64",
          "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64",
          "Debian-10:rsync-0:3.1.3-6.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53785"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-pph3-7xmf-rrqg",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-pph3-7xmf-rrqg"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-path-traversal-write-escape-via-relative-mode",
          "url": "https://www.vulncheck.com/advisories/rsync-path-traversal-write-escape-via-relative-mode"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-27T14:52:47.147410Z",
          "details": "We are not fixing this on this platform because there is no self-contained fix to take. Upstream addressed it by replacing the program's path handling wholesale in a later release and re-pointing every call site at it; importing that would rewrite every file-creation path in the sending and receiving code, the highest-risk area of the program. The flaw needs the relative-paths option together with either a malicious sending side or a local attacker racing a parent directory of the destination; the implied parent directories, and the transferred file, can then be created outside the destination tree. To stay safe, avoid the relative-paths option when pulling from a peer you do not trust into a tree whose parents others can write, and refuse that option on daemon modules that do not need it.",
          "product_ids": [
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els1.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els2.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els3.amd64",
            "Debian-10:rsync-0:3.1.3-6+tuxcare.els4.amd64",
            "Debian-10:rsync-0:3.1.3-6.amd64"
          ]
        }
      ]
    }
  ]
}