rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the pipe-based line-oriented protocol to cause the rsync daemon to process attacker-influenced data as legitimate protocol input, corrupting uid/gid mapping logic.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user or group names containing newline characters. Attackers can inject malicious newline characters into names communicated over the pipe-based line-oriented protocol to cause the rsync daemon to process attacker-influenced data as legitimate protocol input, corrupting uid/gid mapping logic. | |
| Title | rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:36:43.279Z
Reserved: 2026-06-10T20:14:32.827Z
Link: CVE-2026-53788
No data.
Status : Received
Published: 2026-08-13T15:19:42.870
Modified: 2026-08-13T15:19:42.870
Link: CVE-2026-53788
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z