{"id":"CLSA-2026-1779869103","summary":"Fix CVE(s): CVE-2024-12086, CVE-2026-29518, CVE-2026-43618","details":"   * SECURITY UPDATE: receiver process memory disclosure via compressed-token\n     integer overflow:\n     - debian/patches/els/0004-CVE-2026-43618.patch: cap rx_token at\n       MAX_TOKEN_INDEX; reject out-of-range token values.\n     - CVE-2026-43618.\n   * SECURITY UPDATE: malicious server can enumerate arbitrary client files\n     via crafted checksum responses:\n     - debian/patches/els/0005-CVE-2024-12086.patch: add secure_relative_open()\n       and route the receiver's basis-file open through it.\n     - CVE-2024-12086.\n   * SECURITY UPDATE: daemon TOCTOU symlink race on parent path components\n     when \"use chroot = no\":\n     - debian/patches/els/0006-CVE-2026-29518.patch: gate sender/receiver\n       opens and chmods through secure_relative_open() / do_chmod_at().\n     - CVE-2026-29518.","modified":"2026-06-04T09:45:29.739523298Z","published":"2026-05-27T08:05:13Z","upstream":["CVE-2024-12086","CVE-2026-29518","CVE-2026-43618"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779869103.html"}],"affected":[{"package":{"name":"rsync","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/rsync?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-6+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779869103.json"}}],"schema_version":"1.7.5"}