rsync-3.2.5-3.el9_7.2

エラータID: AXSA:2026-396:01

Release date: 
Friday, April 3, 2026 - 16:33
Subject: 
rsync-3.2.5-3.el9_7.2
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

* rsync: Rsync: Out of bounds array access via negative index (CVE-2025-10158)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-10158
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rsync-3.2.5-3.el9_7.2.src.rpm
    MD5: 2963185c20fadb1d536f79d4b6cac3f9
    SHA-256: 7c4163368e91eea4c6e357132ea86ba39b21709018565015b51dca1a38649e38
    Size: 1.25 MB

Asianux Server 9 for x86_64
  1. rsync-3.2.5-3.el9_7.2.x86_64.rpm
    MD5: 8400e59000b9eedf0c5ba5e51dc090f9
    SHA-256: 96bcf1cc66cbe7c8e66b877cedeb33551c8f4a84c82e4022fe16e72bbdb2243b
    Size: 410.86 kB
  2. rsync-daemon-3.2.5-3.el9_7.2.noarch.rpm
    MD5: 0b21a5f21a792aaeaf6f417b4a03ba65
    SHA-256: a8fced48790856aa3312cca5b420b6a53f1d3a7ac0fefcff3e9b683a5856bf7b
    Size: 9.34 kB
  3. rsync-rrsync-3.2.5-3.el9_7.2.noarch.rpm
    MD5: 13649579cd08f249de44419042a8b25f
    SHA-256: b5839d59de5de6d00417b6ba60d560586cd4d15b71f0e7f7be6dffe67bf43834
    Size: 14.49 kB