RHSA-2026:25190HighCVSS 7.4

Red Hat Security Advisory: rsync security update

Published
June 11, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-41035 — rsync: Rsync: Use-after-free vulnerability in extended attribute handling

🎯 Affected products12

  • Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • rsync-0:3.1.3-14.el8_6.10.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • rsync-0:3.1.3-14.el8_6.10.src as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • rsync-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • rsync-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • rsync-daemon-0:3.1.3-14.el8_6.10.noarch as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • rsync-daemon-0:3.1.3-14.el8_6.10.noarch as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • rsync-debuginfo-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • rsync-debuginfo-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)
  • rsync-debugsource-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.6)
  • rsync-debugsource-0:3.1.3-14.el8_6.10.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, avoid using the -X or --xattrs options with rsync if extended attribute handling is not essential for your operations. Disabling these options prevents the vulnerable code path from being exercised. This may impact functionality that relies on extended attributes.

🔗 References (4)