{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* PACKAGING FIX: rsync daemon default group on stock Ubuntu/Debian (ELSR-8050)\n     - the daemon's compile-time NOBODY_GROUP was resolved to \"nobody\" by the\n       focal build chroot's /etc/group, but stock Ubuntu/Debian have only\n       \"nogroup\", so daemon modules with no explicit gid were rejected with\n       \"@ERROR: invalid gid nobody\" (test_daemon / ELSR-8050)\n     - debian/rules: build with rsync's own --with-nobody-group=nogroup\n       configure option so the compile-time NOBODY_GROUP default is baked as\n       \"nogroup\" regardless of the build chroot, matching the stock\n       Ubuntu/Debian rsync build (fixes modules with no explicit gid)\n     - debian/patches/rsync-daemon-nobody-group-fallback.patch: in the daemon's\n       add_a_group() resolve a \"nobody\" group to \"nogroup\" at runtime when the\n       host has no \"nobody\" group, so a module that explicitly sets\n       \"gid = nobody\" is also honoured on stock Ubuntu/Debian instead of being\n       rejected with \"@ERROR: invalid gid nobody\"; any other unresolvable group\n       is still rejected\n     - upstream: configure.ac AC_ARG_WITH(nobody-group)\n       https://github.com/RsyncProject/rsync/blob/v3.1.3/configure.ac#L142-L157\n       Debian bugs #144570 (https://bugs.debian.org/144570) and #25299\n     - ELSR-8050",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu20.04els/advisories/2026/clsa-2026_1782739272.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-29T13:22:06Z",
      "generator": {
        "date": "2026-06-29T13:22:06Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1782739272",
      "initial_release_date": "2026-06-29T13:22:06Z",
      "revision_history": [
        {
          "date": "2026-06-29T13:22:06Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-29518, CVE-2026-41035"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 20.04",
                "product": {
                  "name": "Ubuntu 20.04",
                  "product_id": "Ubuntu-20",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64",
                  "product_id": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-8ubuntu0.9%2Btuxcare.els4?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64",
                "product": {
                  "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64",
                  "product_id": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.1.3-8ubuntu0.9%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
        },
        "product_reference": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64"
        },
        "product_reference": "rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-29518",
      "cwe": {
        "id": "CWE-367",
        "name": "Time-of-check Time-of-use (TOCTOU) Race Condition"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
        ],
        "known_affected": [
          "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-29518"
        }
      ],
      "release_date": "2026-05-20T13:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-29T13:21:15.510262Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272",
          "product_ids": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272"
        },
        {
          "category": "none_available",
          "date": "2026-05-20T13:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-41035",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "category": "description",
          "text": "In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
        ],
        "known_affected": [
          "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-41035"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/issues/871",
          "url": "https://github.com/RsyncProject/rsync/issues/871"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases",
          "url": "https://github.com/RsyncProject/rsync/releases"
        },
        {
          "category": "external",
          "summary": "https://www.openwall.com/lists/oss-security/2026/04/16/2",
          "url": "https://www.openwall.com/lists/oss-security/2026/04/16/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/16/9",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/16/9"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/22/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/22/3"
        }
      ],
      "release_date": "2026-04-16T07:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-29T13:21:15.510262Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272",
          "product_ids": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1782739272"
        },
        {
          "category": "none_available",
          "date": "2026-04-16T07:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els1.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-20:rsync-0:3.1.3-8ubuntu0.9+tuxcare.els4.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}