Linuxsecurity Debian rsync Vulnerabilities Lead to Privilege Escalation and DoS Risks
Article Content
- •Critical vulnerabilities in rsync affect Debian 11, 12, and 13 distributions.
- •Issues include local privilege escalation, denial of service, and remote memory disclosure.
- •Users are urged to upgrade rsync to the latest patched versions immediately.
Multiple vulnerabilities were identified in the rsync tool, affecting Debian 11 (bullseye), Debian 12 (bookworm), and Debian 13 (trixie). These vulnerabilities could lead to local privilege escalation, denial of service, and remote memory disclosure. For Debian 11, the issues were addressed in version 3.2.3-4+deb11u4, while Debian 12 and 13 received updates in versions 3.2.7-1+deb12u5 and 3.4.1+ds1-5+deb13u3, respectively. Users are advised to upgrade their rsync packages to mitigate these risks. The vulnerabilities affect systems running these Debian versions and could be exploited by authenticated users. Detailed security advisories are available for further guidance on applying the updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Debian in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…