FreeBSD : net/rsync -- multiple vulnerabilities (fee67ad5-a05e-11f1-ad2b-40b034429ecf)

critical Nessus Plugin ID 341069

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the fee67ad5-a05e-11f1-ad2b-40b034429ecf advisory.

rsync project reports:
This release fixes 33 security issues found during a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers -- plus several robustness hardenings. CVE IDs were assigned by VulnCheck (CNA); the precise introduced in version ranges accompany each advisory, and many are much narrower than everything before 3.5.0. Every fix ships with a regression test in the test suite that fails on the unfixed tree.
support/rrsync (the restricted SSH wrapper):
Daemon protocol / identity:
Injection and memory safety:
Peer-triggerable memory corruption in the daemon protocol:
Daemon availability and access control:
Client-side:

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2026-53783

https://nvd.nist.gov/vuln/detail/CVE-2026-53784

https://nvd.nist.gov/vuln/detail/CVE-2026-53785

https://nvd.nist.gov/vuln/detail/CVE-2026-53786

https://nvd.nist.gov/vuln/detail/CVE-2026-53788

https://nvd.nist.gov/vuln/detail/CVE-2026-53789

https://nvd.nist.gov/vuln/detail/CVE-2026-53790

https://nvd.nist.gov/vuln/detail/CVE-2026-53791

https://nvd.nist.gov/vuln/detail/CVE-2026-53792

https://nvd.nist.gov/vuln/detail/CVE-2026-53793

https://nvd.nist.gov/vuln/detail/CVE-2026-53794

https://nvd.nist.gov/vuln/detail/CVE-2026-53795

https://nvd.nist.gov/vuln/detail/CVE-2026-53796

https://nvd.nist.gov/vuln/detail/CVE-2026-53797

https://nvd.nist.gov/vuln/detail/CVE-2026-53798

https://nvd.nist.gov/vuln/detail/CVE-2026-53799

https://nvd.nist.gov/vuln/detail/CVE-2026-53800

https://nvd.nist.gov/vuln/detail/CVE-2026-53801

https://nvd.nist.gov/vuln/detail/CVE-2026-53802

https://nvd.nist.gov/vuln/detail/CVE-2026-53803

https://nvd.nist.gov/vuln/detail/CVE-2026-70452

https://nvd.nist.gov/vuln/detail/CVE-2026-70453

https://nvd.nist.gov/vuln/detail/CVE-2026-70454

https://nvd.nist.gov/vuln/detail/CVE-2026-70455

https://nvd.nist.gov/vuln/detail/CVE-2026-70456

https://nvd.nist.gov/vuln/detail/CVE-2026-70457

https://nvd.nist.gov/vuln/detail/CVE-2026-70458

https://nvd.nist.gov/vuln/detail/CVE-2026-70459

https://nvd.nist.gov/vuln/detail/CVE-2026-70460

https://nvd.nist.gov/vuln/detail/CVE-2026-70461

https://nvd.nist.gov/vuln/detail/CVE-2026-70462

https://nvd.nist.gov/vuln/detail/CVE-2026-70463

https://nvd.nist.gov/vuln/detail/CVE-2026-70464

http://www.nessus.org/u?b5391617

Plugin Details

Severity: Critical

ID: 341069

File Name: freebsd_pkg_fee67ad5a05e11f1ad2b40b034429ecf.nasl

Version: 1.1

Type: Local

Published: 8/27/2026

Updated: 8/27/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.18

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-53795

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-53791

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-70460

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:rsync

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-53783, CVE-2026-53784, CVE-2026-53785, CVE-2026-53786, CVE-2026-53788, CVE-2026-53789, CVE-2026-53790, CVE-2026-53791, CVE-2026-53792, CVE-2026-53793, CVE-2026-53794, CVE-2026-53795, CVE-2026-53796, CVE-2026-53797, CVE-2026-53798, CVE-2026-53799, CVE-2026-53800, CVE-2026-53801, CVE-2026-53802, CVE-2026-53803, CVE-2026-70452, CVE-2026-70453, CVE-2026-70454, CVE-2026-70455, CVE-2026-70456, CVE-2026-70457, CVE-2026-70458, CVE-2026-70459, CVE-2026-70460, CVE-2026-70461, CVE-2026-70462, CVE-2026-70463, CVE-2026-70464