Debian rsync Vulnerabilities Lead to Privilege Escalation and DoS Risks

Debian rsync Vulnerabilities Lead to Privilege Escalation and DoS Risks

First seen 21 May 2026, 03:26 UTC Linuxsecurity 83% similarity 57.8

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were identified in the rsync tool, affecting Debian 11 (bullseye), Debian 12 (bookworm), and Debian 13 (trixie). These vulnerabilities could lead to local privilege escalation, denial of service, and remote memory disclosure. For Debian 11, the issues were addressed in version 3.2.3-4+deb11u4, while Debian 12 and 13 received updates in versions 3.2.7-1+deb12u5 and 3.4.1+ds1-5+deb13u3, respectively. Users are advised to upgrade their rsync packages to mitigate these risks. The vulnerabilities affect systems running these Debian versions and could be exploited by authenticated users. Detailed security advisories are available for further guidance on applying the updates.

Key Points: • Critical vulnerabilities in rsync affect Debian 11, 12, and 13 distributions. • Issues include local privilege escalation, denial of service, and remote memory disclosure. • Users are urged to upgrade rsync to the latest patched versions immediately.

ThreatCluster AI

Timeline

2026-05-20
Debian releases security advisory for rsync vulnerabilities
Debian published advisories DLA-4591 for bullseye and DSA-6282 for bookworm and trixie, detailing vulnerabilities and fixes.
Linuxsecurity
2026-05-20
Patched versions released for affected Debian distributions
Debian 11 fixed in version 3.2.3-4+deb11u4, Debian 12 in 3.2.7-1+deb12u5, and Debian 13 in 3.4.1+ds1-5+deb13u3.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story