[CLSA-2026:1789580327] rsync: Fix of CVE-2026-70456
Type:
security
Severity:
Important
Release date:
2026-09-16 17:38:58 UTC
Description:
- CVE-2026-70456: reserve room for the trailing NULL before read_args stores it, so a post-dot daemon request that lands argc on maxargs cannot write one slot past the argv allocation
CVEs fixed:
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:e5df7c81772badd49b0d312db33e43aab1d95e090a55ece2b722e547e0d7cc69
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.