rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rsync | Samba | * | 3.5.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | rsync-0:3.5.0-3.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |