[CLSA-2026:1789601341] rsync: Fix of CVE-2026-70456
Type:
security
Severity:
Important
Release date:
2026-09-16 23:29:13 UTC
Description:
- CVE-2026-70456: reserve room for the trailing NULL before read_args stores it, so a post-dot daemon request that lands argc on maxargs cannot write one slot past the argv allocation
CVEs fixed:
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:75933c6a10a2250147346a007f716f247e0c2436b96ea3a9d4048e9f7fd8021f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.