[El-errata] ELSA-2026-67463-0 Important: Oracle Linux 10 rsync security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Sep 17 13:45:19 UTC 2026


Oracle Linux Security Advisory ELSA-2026-67463-0

http://linux.oracle.com/errata/ELSA-2026-67463-0.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
rsync-3.5.0-3.el10_2.x86_64.rpm
rsync-daemon-3.5.0-3.el10_2.noarch.rpm
rsync-rrsync-3.5.0-3.el10_2.noarch.rpm

aarch64:
rsync-3.5.0-3.el10_2.aarch64.rpm
rsync-daemon-3.5.0-3.el10_2.noarch.rpm
rsync-rrsync-3.5.0-3.el10_2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/rsync-3.5.0-3.el10_2.src.rpm

Related CVEs:

CVE-2026-53783
CVE-2026-53784
CVE-2026-53785
CVE-2026-53789
CVE-2026-53790
CVE-2026-53791
CVE-2026-53793
CVE-2026-53795
CVE-2026-53802
CVE-2026-53803
CVE-2026-70452
CVE-2026-70453
CVE-2026-70454
CVE-2026-70455
CVE-2026-70456
CVE-2026-70457
CVE-2026-70458
CVE-2026-70460
CVE-2026-70461
CVE-2026-70463
CVE-2026-70464




Description of changes:

[3.5.0-3]
- Related: RHEL-246094 - O_PATH for directory travesal full fix

[3.5.0-2]
- Related: RHEL-246094 - O_PATH for directory traversal

[3.5.0-1]
- Resolves: RHEL-246094 - Rebase rsync to version 3.5.0 in RHEL10
- Resolves: RHEL-245337 - Directory escape via TOCTOU (CVE-2026-53783)
- Resolves: RHEL-244599 - Arbitrary file write (CVE-2026-53785)
- Resolves: RHEL-246095 - Command injection (CVE-2026-53790)
- Resolves: RHEL-246065 - Daemon IP spoofing (CVE-2026-53791)
- Resolves: RHEL-244718 - Local privilege escalation (CVE-2026-53803)
- Resolves: RHEL-244797 - DoS via algorithmic complexity (CVE-2026-70453)
- Resolves: RHEL-245247 - DoS via Zstandard compression (CVE-2026-70455)
- Resolves: RHEL-245188 - Heap out-of-bounds write (CVE-2026-70456)
- Resolves: RHEL-245313 - Information disclosure and DoS (CVE-2026-70461)




More information about the El-errata mailing list