Skip to content
SUSE 2026-3634

SUSE 2026-3634

Linuxsecurity LinuxSecurity Advisories August 18, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for rsync fixes the following issues: * CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). * CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" (bsc#1269042). * CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). * CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). * CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). * CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). * CVE-2026-53790: Command / argument injection via unquoted peer- or host- controlled values (bsc#1269048).

## This update for rsync fixes the following issues: * CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). * CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" (bsc#1269042). * CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). * CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). * CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). * CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). * CVE-2026-53790: Command / argument injection via unquoted peer- or host- controlled values (bsc#1269048).

Announcement ID: SUSE-SU-2026:3634-1 Release Date: 2026-08-17T19:04:03Z Rating: important

Get the latest Linux and open source security news straight to your inbox.