AlmaLinux 9.6 [TuxCare] Security Update: rsync / rsync-daemon / rsync-rrsync Multiple Vulnerabilities (ALMALINUX9.6:CLSA-2026:1789783256)

critical Nessus Plugin ID 353044

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.6:CLSA-2026:1789783256 advisory.

- rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in
--relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem. (CVE-2026-53785)

- rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user- supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user. (CVE-2026-53790)

- rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap.
Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service.
(CVE-2026-53794)

- rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service. (CVE-2026-70453)

- rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. (CVE-2026-70456)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.6:CLSA-2026:1789783256.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1789783256

http://www.nessus.org/u?21890ab4

Plugin Details

Severity: Critical

ID: 353044

File Name: tuxcare_alma_linux_9.6_CLSA-2026-1789783256.nasl

Version: 1.2

Type: Local

Published: 9/30/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.18

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2026-70458

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-53790

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 9/19/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-53785, CVE-2026-53790, CVE-2026-53794, CVE-2026-70453, CVE-2026-70456, CVE-2026-70458, CVE-2026-70462

CLSA: 2026:1789783256