You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Deepin Integration]~[v25-Release] fix(rsync): CVE-2026-41035 use-after-free in receive_xattr by deepin-ci-robot@deepin-community/rsync by deepin-community-ci-bot[bot] #13235
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted
length value during a qsort call, leading to a receiver use-after-free.
(Closes: #1134617)
Package information | 软件包信息
Package repository address | 软件包仓库地址
Changelog | 更新信息
rsync (3.4.1+ds1-7deepin1) unstable; urgency=medium
d/p/CVE-2026-41035.patch: Import upstream patch to fix CVE-2026-41035
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted
length value during a qsort call, leading to a receiver use-after-free.
(Closes: #1134617)