{"id":"CLSA-2026-1779694727","summary":"Fix CVE(s): CVE-2026-29518","details":"   * SECURITY UPDATE: daemon-no-chroot TOCTOU symlink race\n     - debian/patches/CVE-2026-29518.patch: track per-module chroot in\n       am_chrooted and use_secure_symlinks; route the sender's read-path\n       open, the receiver's basis-file open, mkstemp, and inplace write\n       through secure_relative_open() / secure_mkstemp()\n     - CVE-2026-29518","modified":"2026-06-04T09:47:32.649187744Z","published":"2026-05-25T07:38:50Z","upstream":["CVE-2026-29518"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2026-1779694727.html"}],"affected":[{"package":{"name":"rsync","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/rsync?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.2-2.1ubuntu1.6+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779694727.json"}}],"schema_version":"1.7.5"}