Multiple vulnerabilities have been discovered in Rsync, the most severe of which could allow for remote code execution. Rsync is an open-source file synchronization and data transferring tool valued for its ability to perform incremental transfers, reducing data transfer times and bandwidth usage. The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution in the context of the system. Depending on the privileges associated with the system, an attacker could then install programs; view, change, or delete data. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
More Stories
libxml2-2.12.10-1.fc40
FEDORA-2025-adbb0031f7 Packages in this update: libxml2-2.12.10-1.fc40 Update description: Update to 2.12.10 Read More
libxml2-2.12.10-1.fc41
FEDORA-2025-65790c11eb Packages in this update: libxml2-2.12.10-1.fc41 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
libxml2-2.12.10-1.fc42
FEDORA-2025-b9170cd464 Packages in this update: libxml2-2.12.10-1.fc42 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
kitty-0.40.0-2.fc40
FEDORA-2025-2fe21e3da5 Packages in this update: kitty-0.40.0-2.fc40 Update description: Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes Read More
USN-7351-1: RESTEasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding when certain errors occur. An attacker could possibly use this issue...
USN-7344-2: Linux kernel vulnerabilities
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could...