Debian Takes rsync 3.5.0 Whole Instead of Backporting 33 CVE Fixes
Security / news
Debian Takes rsync 3.5.0 Whole Instead of Backporting 33 CVE Fixes
The Aug. 13 release closes one critical proxy-protocol bypass and a run of high-rated symlink bugs, and it changes how rsync follows symlinks on backup jobs.

The rsync project released version 3.5.0 on Aug. 13, 2026 with fixes for 33 CVEs, and Debian chose to package the whole release instead of backporting each patch. The one rated critical, CVE-2026-53791, affects only a daemon configured with proxy protocol = true and lets a directly connecting client forge its source address.
The rsync NEWS file says the fixes came from "a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers." Identifiers were assigned by VulnCheck, acting as CVE numbering authority, and each fix ships with a regression test.
CVE-2026-53791 and what it does not do
The NEWS entry reads: "With proxy protocol = true, a client connecting directly (not via the trusted proxy) could send a PROXY header to spoof its source address and bypass host-based access control." A forwarded address is now honoured only from a configured trusted-proxy peer.
The consequence is an access-control bypass, not code execution. An operator who limits a module with hosts allow and also enables proxy protocol, but lets clients reach the daemon without the proxy, had a rule an attacker could talk past. ETTAYEB, a security blog, rates the bug 9.1 and says a daemon with proxy protocol enabled and no trusted hosts now refuses connections.
The symlink bugs in the high tier
Most of the high-rated entries concern symbolic links. The NEWS file lists these among them:
| CVE | Rating | Issue |
|---|---|---|
| CVE-2026-53802 | High | Symlinks in filter merge files and password files allowed arbitrary file reads |
| CVE-2026-53803 | High | Output-path symlinks allowed writes outside the destination tree |
| CVE-2026-53784 | High | Daemon module-root chdir escape without chroot |
| CVE-2026-53793 | High | Chroot inner-module escape through symlinked parents |
| CVE-2026-53795 | High | Absolute temp-dir and link-dest options disabled confinement |
| CVE-2026-53785 | High | Parent directory creation in relative mode |
ETTAYEB adds that fuzzing found heap out-of-bounds writes in filter processing, argument parsing and hard-link handling, reachable through the daemon protocol. That is the claim of one blog, and the NEWS entries it rests on are the place to confirm it.

What changes on a backup job after 3.5.0
The path resolver now follows a symlinked destination only when it is "owned by uid 0 or the effective uid." A backup script that writes through a symlink owned by a third account will behave differently after the upgrade, so test it before the nightly run. The rrsync wrapper also forces --no-D inside restricted subdirectories.
ETTAYEB ranks exposure in three tiers: rsync daemons with proxy protocol enabled as critical, internal daemons on local networks as high, and root-over-SSH backup scripts as moderate. That ranking is the blog's, not the project's. None of the sources reports exploitation in the wild.
Why Debian took the full version
The Lobsters thread on the update says Debian maintainer Samuel Henrique decided the version bump carried "the lower amount of risk" than backporting 33 separate patches. The Debian changelog shows 3.5.0+ds1-1 uploaded to unstable on Aug. 16, 2026. Taking the whole release means taking every behaviour change in it, which is why backup operators should read the notes. Another disclosure the site covered shows how one missing check can matter more than the count of fixes.
Upstream followed with 3.5.1 on Sept. 21, which among other things stops echoing an unparsable filter rule back verbatim, including rules read from a merge file. Debian packaged it as 3.5.1+ds1-1 on Sept. 22. Run 3.5.1 or later, not 3.5.0. Infrastructure software such as the AI gateways CISA listed tends to get an audit like this only after someone looks.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.