CVE – Vulnerabilities in rsync scanner

Two independent groups of researchers have identified a total of 6 vulnerabilities in rsync. In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on.

For more information on these vulnerabilities, please refer to the following resources:

https://vulnerability.circl.lu/bundle/d938dc28-6877-40db-ad5f-25f3051288e6

https://www.openwall.com/lists/oss-security/2025/01/14/3