Major rsync upgrade in Debian because of 33 CVEs
apt-listchanges --which=both -f text --since=3.4.1+ds1-5+deb13u4 /var/cache/apt/archives/rsync_3.5.0+ds1-0+deb13u1_amd64.deb apt-listchanges: Reading changelogs... apt-listchanges: News rsync (3.5.0+ds1-0+deb13u1) trixie-security; urgency=medium In order to fix 33 CVEs, I have decided to bump the package to 3.5.0 rather than backporting all patches individually. After analysing the extra changes…
Debian has released a major rsync upgrade due to 33 critical vulnerabilities (CVEs). The package was upgraded from version 3.4.1+ds1-5+deb13u4 to 3.5.0+ds1-0+deb13u1, rather than backporting patches individually, to minimize risk. This update introduces behavior changes stemming from the CVE fixes, not just the version bump. Notably, operator-supplied paths are no longer followed through untrusted symlinks; the destination directory and various arguments are resolved one component at a time, refusing to follow symlinks owned by untrusted users.
The --insecure-links option is restored but only for trusted modules. Additionally, rrsync will no longer accept the --debug flag. When operating within a subdirectory, rsync will deny the --copy-unsafe-links option, pass the --confine-root directive to restrict server resolution of client-named filter merge files, and disallow device or special file creation via uploads.
Other rsyncd changes include rejecting connections when using the proxy protocol without specifying trusted hosts, and failing closed when resolving a configured hostname that cannot be found. Documentation modifications address various cases, such as host allow/deny patterns folding case inside [...] bracket expressions. Lastly, rsync-ssl now verifies server certificates, and stunnel and gnutls backends require RSYNC_SSL_CA_CERT to be set or insecure options disabled.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.