Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for rsync fixes the following issues: * CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). * CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" (bsc#1269042). * CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). * CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). * CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). * CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). * CVE-2026-53790: Command / argument injection via unquoted peer- or host- controlled values (bsc#1269048).
## This update for rsync fixes the following issues: * CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). * CVE-2026-53784: Daemon module-root chdir escape under "use chroot = no" (bsc#1269042). * CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). * CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). * CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). * CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). * CVE-2026-53790: Command / argument injection via unquoted peer- or host- controlled values (bsc#1269048).
Announcement ID: SUSE-SU-2026:3634-1 Release Date: 2026-08-17T19:04:03Z Rating: important
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
