CentOS Linux 6 [TuxCare] Security Update: rsync Multiple Vulnerabilities (CENTOS6:CLSA-2026:1779824462)

high Nessus Plugin ID 360672

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 6 host has a package installed that is affected by multiple vulnerabilities as referenced in the TuxCare CENTOS6:CLSA-2026:1779824462 advisory.

- Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false. (CVE-2026-29518)

- Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds.
Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. (CVE-2026-43618)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected rsync package based on the guidance in TuxCare advisory CENTOS6:CLSA-2026:1779824462.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1779824462

http://www.nessus.org/u?37727e91

Plugin Details

Severity: High

ID: 360672

File Name: tuxcare_centos_6_CLSA-2026-1779824462.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.26

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2026-43618

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 4.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-29518

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 5/26/2026

Vulnerability Publication Date: 5/20/2026

Reference Information

CVE: CVE-2026-29518, CVE-2026-43618

CLSA: 2026:1779824462