FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

net/rsync -- multiple vulnerabilities

Affected packages
rsync < 3.5.0

Details

VuXML ID fee67ad5-a05e-11f1-ad2b-40b034429ecf
Discovery 2026-08-13
Entry 2026-08-25

rsync project reports:

This release fixes 33 security issues found during a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers -- plus several robustness hardenings. CVE IDs were assigned by VulnCheck (CNA); the precise "introduced in" version ranges accompany each advisory, and many are much narrower than "everything before 3.5.0". Every fix ships with a regression test in the test suite that fails on the unfixed tree.

support/rrsync (the restricted SSH wrapper):

Daemon protocol / identity:

Injection and memory safety:

Peer-triggerable memory corruption in the daemon protocol:

Daemon availability and access control:

Client-side:

References

CVE Name CVE-2026-53783
CVE Name CVE-2026-53784
CVE Name CVE-2026-53785
CVE Name CVE-2026-53786
CVE Name CVE-2026-53788
CVE Name CVE-2026-53789
CVE Name CVE-2026-53790
CVE Name CVE-2026-53791
CVE Name CVE-2026-53792
CVE Name CVE-2026-53793
CVE Name CVE-2026-53794
CVE Name CVE-2026-53795
CVE Name CVE-2026-53796
CVE Name CVE-2026-53797
CVE Name CVE-2026-53798
CVE Name CVE-2026-53799
CVE Name CVE-2026-53800
CVE Name CVE-2026-53801
CVE Name CVE-2026-53802
CVE Name CVE-2026-53803
CVE Name CVE-2026-70452
CVE Name CVE-2026-70453
CVE Name CVE-2026-70454
CVE Name CVE-2026-70455
CVE Name CVE-2026-70456
CVE Name CVE-2026-70457
CVE Name CVE-2026-70458
CVE Name CVE-2026-70459
CVE Name CVE-2026-70460
CVE Name CVE-2026-70461
CVE Name CVE-2026-70462
CVE Name CVE-2026-70463
CVE Name CVE-2026-70464
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53783
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53784
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53785
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53786
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53788
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53789
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53790
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53791
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53792
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53793
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53794
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53795
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53796
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53797
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53798
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53799
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53800
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53801
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53802
URL https://nvd.nist.gov/vuln/detail/CVE-2026-53803
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70452
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70453
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70454
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70455
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70456
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70457
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70458
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70459
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70460
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70461
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70462
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70463
URL https://nvd.nist.gov/vuln/detail/CVE-2026-70464