rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the modules subtree.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | rsync-0:3.5.0-3.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | rsync-0:3.2.7-1.el9_8 | * |