- Sources: rsync NEWS, release v3.5.0
- Summary: rsync 3.5.0 was released on 2026-08-13 and fixes 33 security issues, with CVE IDs assigned by VulnCheck and per-issue introduced-in ranges narrower than a blanket everything before 3.5.0. CVE-2026-53791 lets a client that connects directly to a daemon running with
proxy protocol = true send its own PROXY header, spoof a source address, and bypass host-based access control, and five further daemon flaws are peer-triggerable memory corruption reachable from the wire, four of them writes, found in a fuzzing pass reported by Greg Kroah-Hartman. Further high-severity issues cover an rrsync restricted-directory escape, argument injection through RSYNC_CONNECT_PROG and daemon exec hooks, and hosts deny failing open when a hostname does not resolve. rsync NEWS rates CVE-2026-70454, rsync-ssl establishing TLS with no certificate verification and no hostname binding, as medium rather than high. - Why it matters: rsync ships on nearly every Unix system and sits inside backup, mirror, and CI pipelines, so a daemon access-control bypass alongside wire-reachable memory corruption reaches infrastructure that is rarely tracked against a release cadence.
- Follow-up: Track distribution backports, whether the residual path-based ACL and xattr behaviour on the BSDs, macOS, Solaris, and proc-less containers draws its own advisory, and whether any daemon memory-corruption CVE sees exploitation.
send feedback on this story