Skip to content

Update rsync to 3.5.0 - #603

Merged
bryan-minimal merged 1 commit into
mainfrom
update-rsync-3.5.0
Aug 13, 2026
Merged

Update rsync to 3.5.0#603
bryan-minimal merged 1 commit into
mainfrom
update-rsync-3.5.0

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update rsync 3.4.43.5.0

Source: github:RsyncProject/rsync:release-asset
Release: https://github.com/RsyncProject/rsync/releases/tag/v3.5.0
Changelog: RsyncProject/rsync@v3.4.4...v3.5.0
Released: 14 hours ago (2026-08-13)

Pkgscan: clean — diff against the prior version surfaced no newly-introduced suspicious patterns.

Vulnerability impact

Partition analysis at 3.5.0 (uses each advisory's fixed-version, vulnerable-range, affected-ranges, and fix-commit ancestry to decide):

  • 33 cleared — the new version is outside the advisory's affected range, OR the tag's lineage includes a known fix-commit. These will drop off the next scan.

Vulnerabilities fixed (33)

This update clears 33 vulnerabilities affecting 3.4.4:

CVE / GHSA Severity Fixed in
GHSA-h2q9-5fr8-w635 CRITICAL via range: <= 3.4.4; <= 3.4.4
GHSA-4mfr-8jrv-49x4 HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-5hcf-7xxm-rmqq HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-6692-28cx-wpqq HIGH via range: >= 3.1.0, <= 3.4.4; >= 3.1.0, <= 3.4.4
GHSA-78jc-79jv-v6rw HIGH via range: >= 3.0.1, <= 3.4.4; >= 3.0.1, <= 3.4.4
GHSA-8x5r-mjx8-83hv HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-9cgc-64g4-3gv5 HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-ffg2-fr5g-3rxw HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-g9f4-7q66-9582 HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-gg3m-4m9m-268h HIGH via range: >= 3.0.0, <= 3.4.4; >= 3.0.0, <= 3.4.4
GHSA-hrwq-ccf7-rw5m HIGH via range: >= 2.0.0, <= 3.4.4; >= 2.0.0, <= 3.4.4
GHSA-jhxm-j4mq-3fj4 HIGH via range: >= 3.2.5, <= 3.4.4; >= 3.2.5, <= 3.4.4
GHSA-m9vj-637x-v6pq HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-pfj8-79vq-xgvr HIGH via range: >= 3.1.0, <= 3.4.4; >= 3.1.0, <= 3.4.4
GHSA-pph3-7xmf-rrqg HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-rjvj-qgqg-cvx9 HIGH via range: >= 3.4.2, <= 3.4.4; >= 3.4.2, <= 3.4.4
GHSA-w3xf-j2r2-gv4x HIGH via range: >= 2.3.3, <= 3.4.4; >= 2.3.3, <= 3.4.4
GHSA-wj7w-vh23-mm44 HIGH via range: <= 3.4.4; <= 3.4.4
GHSA-3c3x-ww2w-5r5p MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-3jj3-qvc7-jp6x MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-cg57-rp9g-56hw MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-fxwg-7hmf-xh5q MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-hx7p-3gvv-pqgv MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-j9wh-5jmp-2m64 MEDIUM via range: >= 3.1.0, <= 3.4.4; >= 3.1.0, <= 3.4.4
GHSA-mch3-qr4p-chgm MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-mrc3-6cwx-hch6 MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-p4c5-8c68-5fjq MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-p4v4-qxw9-q72m MEDIUM via range: >= 3.0.0, <= 3.4.4; >= 3.0.0, <= 3.4.4
GHSA-p827-vwcp-m964 MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-pg7g-xqmr-xpfh MEDIUM via range: >= 3.2.3, <= 3.4.4; >= 3.2.3, <= 3.4.4
GHSA-phxh-hjqv-39c9 MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-v3vw-pvpg-chwh MEDIUM via range: <= 3.4.4; <= 3.4.4
GHSA-w75h-ccff-w53m MEDIUM via range: <= 3.4.4; <= 3.4.4
Advisory summaries
  • GHSA-h2q9-5fr8-w635 — rsync: PROXY-protocol mode lets a direct client spoof the daemon's source address (Published 2026-08-13)
  • GHSA-4mfr-8jrv-49x4 — rsync: arbitrary file read / transfer-shaping via symlinked operator-supplied input files (Published 2026-08-13)
  • GHSA-5hcf-7xxm-rmqq — rsync: command / argument injection via unquoted peer- or host-controlled values (Published 2026-08-13)
  • GHSA-6692-28cx-wpqq — rsync: hosts deny fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (Published 2026-08-13)
  • GHSA-78jc-79jv-v6rw — rsync: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (Published 2026-08-13)
  • GHSA-8x5r-mjx8-83hv — rsync: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (Published 2026-08-13)
  • GHSA-9cgc-64g4-3gv5 — rsync: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (Published 2026-08-13)
  • GHSA-ffg2-fr5g-3rxw — rsync: daemon module-root chdir escape under "use chroot = no" (Published 2026-08-13)
  • GHSA-g9f4-7q66-9582 — rsync: arbitrary file write / privilege escalation via symlinked operator-supplied output paths (Published 2026-08-13)
  • GHSA-gg3m-4m9m-268h — rsync: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (Published 2026-08-13)
  • GHSA-hrwq-ccf7-rw5m — rsync: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (Published 2026-08-13)
  • GHSA-jhxm-j4mq-3fj4 — rsync: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (Published 2026-08-13)
  • GHSA-m9vj-637x-v6pq — rsync: receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (Published 2026-08-13)
  • GHSA-pfj8-79vq-xgvr — rsync: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule (Published 2026-08-13)
  • GHSA-pph3-7xmf-rrqg — rsync: --relative implied-parent creation escapes the destination tree (Published 2026-08-13)
  • GHSA-rjvj-qgqg-cvx9 — rsync: Peer-controlled Zstandard worker exhaustion on an rsync daemon (Published 2026-08-13)
  • GHSA-w3xf-j2r2-gv4x — rsync: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink (Published 2026-08-13)
  • GHSA-wj7w-vh23-mm44 — rsync: chroot "/./" inner-module escape via a parent-component symlink (Published 2026-08-13)
  • GHSA-3c3x-ww2w-5r5p — rsync: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding) (Published 2026-08-13)
  • GHSA-3jj3-qvc7-jp6x — rsync: sender source-tree parent-component symlink race -> out-of-tree disclosure (Published 2026-08-13)
  • GHSA-cg57-rp9g-56hw — rsync: receiver-supplied zero checksum block length drives sender matching negative (Published 2026-08-13)
  • GHSA-fxwg-7hmf-xh5q — rsync: malicious sender expands --delete scope by reclassifying an implied parent (Published 2026-08-13)
  • GHSA-hx7p-3gvv-pqgv — rsync: daemon name-converter empty response maps an unknown name to uid/gid 0 (Published 2026-08-13)
  • GHSA-j9wh-5jmp-2m64 — rsync: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value) (Published 2026-08-13)
  • GHSA-mch3-qr4p-chgm — rsync: sender/daemon directory-scan enumeration escapes the transfer root/module -> out-of-tree disclosure (Published 2026-08-13)
  • GHSA-mrc3-6cwx-hch6 — rsync: daemon --filter merge file bypasses the module filter list (Published 2026-08-13)
  • GHSA-p4c5-8c68-5fjq — rsync: daemon name-converter accepts newline-bearing names into its line protocol (Published 2026-08-13)
  • GHSA-p4v4-qxw9-q72m — rsync: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (Published 2026-08-13)
  • GHSA-p827-vwcp-m964 — rsync: remote peer disables the per-allocation sanity cap via --max-alloc=0 (Published 2026-08-13)
  • GHSA-pg7g-xqmr-xpfh — rsync: Attacker-chosen-offset write in parse_size_arg() error formatting (Published 2026-08-13)
  • GHSA-phxh-hjqv-39c9 — rsync: receiver ACL/xattr metadata apply follows a symlink race -> arbitrary ACL set (local privilege escalation) (Published 2026-08-13)
  • GHSA-v3vw-pvpg-chwh — rsync: --remove-source-files unlink follows a parent-component symlink race -> file deletion outside the source tree (Published 2026-08-13)
  • GHSA-w75h-ccff-w53m — rsync: non-daemon receiver destination-chdir symlink race (TOCTOU) (Published 2026-08-13)

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ rsync 3.4.4 3.5.0
~ rsync-upstream 3.4.4 3.5.0

Changes

Old New
Version 3.4.4 3.5.0
SHA256 bd88cf82fa653da3... c7ffd1ef653e9954...
Size 1.9 MB
Source https://github.com/RsyncProject/rsync/releases/download/v3.4.4/rsync-3.4.4.tar.gz https://github.com/RsyncProject/rsync/releases/download/v3.5.0/rsync-3.5.0.tar.gz
  • License: GPL-3.0-only (source: tarball)

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

@bryan-minimal
bryan-minimal added this pull request to the merge queue Aug 13, 2026
Merged via the queue into main with commit 8b9b106 Aug 13, 2026
9 checks passed
@bryan-minimal
bryan-minimal deleted the update-rsync-3.5.0 branch August 13, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants