The vendor explicitly identifies these products as affected by this CVE.
- rsync as a component of Red Hat Enterprise Linux 10
- rsync-daemon as a component of Red Hat Enterprise Linux 10
- rsync-rrsync as a component of Red Hat Enterprise Linux 10
- rsync.src as a component of Red Hat Enterprise Linux 10
- rsync as a component of Red Hat Enterprise Linux 6
- rsync.src as a component of Red Hat Enterprise Linux 6
- rsync as a component of Red Hat Enterprise Linux 7
- rsync.src as a component of Red Hat Enterprise Linux 7
- rsync as a component of Red Hat Enterprise Linux 8
- rsync-daemon as a component of Red Hat Enterprise Linux 8
- rsync.src as a component of Red Hat Enterprise Linux 8
- rsync as a component of Red Hat Enterprise Linux 9
- Summary
- A time-of-check to time-of-use (TOCTOU) race condition flaw in the rrsync restricted shell wrapper allows authenticated remote attackers to escape directory restrictions. By replacing a validated path component with a symbolic link prior to file transfer execution, an attacker can bypass intended boundary controls and read or write arbitrary files outside the designated directory.
- Remediation
- Do not use the rrsync SSH forced-command wrapper until patched packages are applied. If restricted rsync over SSH is strictly required, grant access only to SSH identities that are fully trusted with the host account's entire filesystem privileges, as rrsync cannot safely enforce directory boundaries. Note that standard rsync daemon firewall controls (TCP 873) do not mitigate this flaw, as execution occurs entirely over SSH (TCP 22).
