[CLSA-2026:1789579460] rsync: Fix of CVE-2026-70456
Type:
security
Severity:
Important
Release date:
2026-09-16 17:24:31 UTC
Description:
- CVE-2026-70456: reserve room for the trailing NULL before read_args stores it, so a post-dot daemon request that lands argc on maxargs cannot write one slot past the argv allocation
CVEs fixed:
Updated packages:
  • rsync-3.1.2-12.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:da6eb7421ec647b54b86c7510860a89b5fd92e80a8e1c79a5dc74457521a8a3f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.