{"id":"SUSE-SU-2026:2048-1","summary":"Security update for rsync","details":"This update for rsync fixes the following issues\n\n- CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511).\n- CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515).\n- CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512).\n- CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513).\n- CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296).\n","modified":"2026-05-26T08:15:04.806902582Z","published":"2026-05-25T13:55:42Z","related":["CVE-2024-12084","CVE-2024-12085","CVE-2024-12086","CVE-2024-12087","CVE-2024-12088","CVE-2024-12747","CVE-2025-10158","CVE-2026-29518","CVE-2026-41035","CVE-2026-43617","CVE-2026-43618","CVE-2026-43620","CVE-2026-45232"],"upstream":["CVE-2024-12084","CVE-2024-12085","CVE-2024-12086","CVE-2024-12087","CVE-2024-12088","CVE-2024-12747","CVE-2025-10158","CVE-2026-29518","CVE-2026-41035","CVE-2026-43617","CVE-2026-43618","CVE-2026-43620","CVE-2026-45232"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262048-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234101"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234102"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234103"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234104"},{"type":"REPORT","url":"https://bugzilla.suse.com/1235475"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264511"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264513"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12085"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12747"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41035"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45232"}],"schema_version":"1.7.5"}