Rsync 3.5 lands as "extraordinary" release patching 33 security flaws

Rsync 3.5 lands as "extraordinary" release patching 33 security flaws

Rsync, the widely used open-source utility for synchronizing files and directories across networks, has received a major update. Version 3.5 is described in the official release notes as an "extraordinary release," a designation driven by the sheer volume of security issues addressed.

The new version ships with 33 security fixes. These flaws were uncovered during a focused audit of the codebase, specifically targeting path handling, the daemon protocol, and related components.

Among the vulnerabilities patched in Rsync 3.5 are arbitrary file read and transfer-shaping attacks via symlinked operator-supplied input files, as well as arbitrary file write and privilege escalation through symlinked operator-supplied output paths. The update also addresses multiple vulnerabilities carrying high CVSS scores. In total, the release notes enumerate all the significant security corrections included in this build.

For users who prefer to compile the software themselves, the latest Rsync 3.5 sources are now available for download via Samba.org. Given the breadth of fixes, upgrading is strongly recommended for anyone relying on Rsync for remote file synchronization, particularly in environments where untrusted data or multi-user access is involved. The project's maintainers have highlighted the importance of this release, urging administrators to apply the update promptly to mitigate potential exploitation risks.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate