{"id":"SUSE-SU-2026:22015-1","summary":"Security update for rsync","details":"This update for rsync fixes the following issues\n\n- CVE-2025-10158: Out of bounds array access via negative index (bsc#1254441).\n- CVE-2026-29518: Symlink-Race TOCTOU in Daemon (use chroot = no) (bsc#1264511).\n- CVE-2026-41035: count of entries mismatch can lead to a use-after-free (bsc#1262223).\n- CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515).\n- CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512).\n- CVE-2026-43619: Symlink Race Condition via Path-Based Syscalls (bsc#1264514).\n- CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513).\n- CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296).\n","modified":"2026-06-09T18:24:43.876661496Z","published":"2026-06-02T09:14:50Z","related":["CVE-2025-10158","CVE-2026-29518","CVE-2026-41035","CVE-2026-43617","CVE-2026-43618","CVE-2026-43619","CVE-2026-43620","CVE-2026-45232"],"upstream":["CVE-2025-10158","CVE-2026-29518","CVE-2026-41035","CVE-2026-43617","CVE-2026-43618","CVE-2026-43619","CVE-2026-43620","CVE-2026-45232"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622015-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264511"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264513"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41035"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45232"}],"affected":[{"package":{"name":"rsync","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"rsync":"3.4.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22015-1.json"}},{"package":{"name":"rsync","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.1-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"rsync":"3.4.1-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22015-1.json"}}],"schema_version":"1.7.5"}