[CLSA-2026:1789576388] rsync: Fix of CVE-2026-70456
Type:
security
Severity:
Important
Release date:
2026-09-16 16:33:18 UTC
Description:
- CVE-2026-70456: reserve room for the trailing NULL before read_args stores it, so a post-dot daemon request that lands argc on maxargs cannot write one slot past the argv allocation
CVEs fixed:
Updated packages:
  • rsync-3.1.2-12.0.1.amzn2.tuxcare.els13.x86_64.rpm
    sha:d30f571dd9f7b76e16bee1923247808b9c219f41d9f4272615d357ed3496b684
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.