Skip to content
Debian rsync Vulnerabilities Lead to Privilege Escalation and DoS Risks

Debian rsync Vulnerabilities Lead to Privilege Escalation and DoS Risks

First seen 21 May 2026, 03:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 22, 2026 at 02:27 UTC
  • Critical vulnerabilities in rsync affect Debian 11, 12, and 13 distributions.
  • Issues include local privilege escalation, denial of service, and remote memory disclosure.
  • Users are urged to upgrade rsync to the latest patched versions immediately.

Multiple vulnerabilities were identified in the rsync tool, affecting Debian 11 (bullseye), Debian 12 (bookworm), and Debian 13 (trixie). These vulnerabilities could lead to local privilege escalation, denial of service, and remote memory disclosure. For Debian 11, the issues were addressed in version 3.2.3-4+deb11u4, while Debian 12 and 13 received updates in versions 3.2.7-1+deb12u5 and 3.4.1+ds1-5+deb13u3, respectively. Users are advised to upgrade their rsync packages to mitigate these risks. The vulnerabilities affect systems running these Debian versions and could be exploited by authenticated users. Detailed security advisories are available for further guidance on applying the updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 121d ago How this analysis works

Timeline

2026-05-20
Debian releases security advisory for rsync vulnerabilities
Debian published advisories DLA-4591 for bullseye and DSA-6282 for bookworm and trixie, detailing vulnerabilities and fixes.
Linuxsecurity
2026-05-20
Patched versions released for affected Debian distributions
Debian 11 fixed in version 3.2.3-4+deb11u4, Debian 12 in 3.2.7-1+deb12u5, and Debian 13 in 3.4.1+ds1-5+deb13u3.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Debian in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed