CVE-2026-53800

Summary

rsync before 3.5.0 contains a symlink race condition vulnerability in the –remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.

Affected Software

VendorProductVersion RangeStatus
RsyncProjectrsync0 <= 3.4.4affected
RsyncProjectrsync3.5.0unaffected

Weaknesses

  • CWE-59: CWE-59 Improper Link Resolution Before File Access ('Link Following')
  • CWE-367: CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

References