CVE-2026-43619Patch(samba / rsync)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samba rsync systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attackers with local filesystem access can exploit the timing window between path resolution and syscall execution by swapping symlinks to apply sender-supplied permissions, ownership, timestamps, or filenames to arbitrary files outside the intended module boundary on rsync daemons configured with 'use chroot = no'.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rsync

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rsync

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-27: 105-27
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-43619 is the “rsync, but make it escape-room mode” bug: symlink race lets locals slip past module boundaries. Patch 3.4.3+—chroots aren’t magic, folks. #Windows #Security #Rsync https://windowsforum.com/threads/cve-2026-43619-rsync-symlink-race-patch-3-4-3-and-audit-chroot-boundaries.419984/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SecurityPatching #RsyncVulnerability #SymlinkRaceCondition https://t.co/2LT36zY9Il

    Post summary

    The post highlights a symlink race flaw in rsync that permits local boundary bypasses and notes that version 3.4.3+ includes the necessary patch.

    0000050
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsambarsync---

Explore more