Major rsync upgrade in Debian because of 33 CVEs

Open in a window
Article lobste.rs

Major rsync upgrade in Debian because of 33 CVEs

apt-listchanges --which=both -f text --since=3.4.1+ds1-5+deb13u4
/var/cache/apt/archives/rsync_3.5.0+ds1-0+deb13u1_amd64.deb apt-listchanges: Reading changelogs... apt-listchanges: News

rsync (3.5.0+ds1-0+deb13u1) trixie-security; urgency=medium

In order to fix 33 CVEs, I have decided to bump the package to 3.5.0 rather than backporting all patches individually. After analysing the extra changes from the bump, not included in the CVE fixes, I have concluded this approach carries the lower amount of risk compared to the alternative.

This update contains behavior changes, all of which stems from the CVE fixes themselves, not exclusive to the version bump. The ones most likely to break an existing setup are listed here; /usr/share/doc/rsync/NEWS.md.gz has the full list.

Operator-supplied paths are no longer followed through untrusted symlinks. The destination directory and the arguments to --backup-dir, --temp-dir, --partial-dir, --link-dest, --compare-dest, --copy-dest, --log-file, --password-file, --files-from, --include-from, --exclude-from, --write-batch, --read-batch and --filter merge files are now resolved one component at a time, following a symlink only when it is owned by root or by the user running rsync; one owned by anyone else is refused with "refusing to follow a symlink owned by an untrusted user". --insecure-links restores the old behaviour, but it is local only and a daemon never honours it. For a single trusted module, set "insecure links = yes" in that module instead.

rrsync now refuses --debug on every invocation. When restricted to a subdirectory it additionally denies --copy-unsafe-links, passes the new --confine-root so the server will not resolve a client-named filter merge file outside that directory, and passes --drop-D when receiving, so an upload can no longer create devices or special files there ("skipping non-regular file"). A plain "rsync -a" otherwise still works.

--chmod=a+s now sets both the setuid and setgid bits, matching chmod(1); it previously set setuid alone.

rsyncd changes that can change who gets in:

  • "proxy protocol = true" without "proxy protocol hosts" now rejects every connection and warns at startup, instead of trusting a client-supplied PROXY header.
  • "hosts deny" now fails closed when a configured hostname cannot be resolved (with "forward lookup", the default), so a host previously admitted by an unresolvable deny entry is now blocked.
  • "auth users" values that start with a comma now split on commas alone, as documented, so a deny or :ro rule naming a group whose name contains a space now takes effect where it was silently ignored.
  • "hosts allow" / "hosts deny" patterns now fold case inside a [...] bracket expression as well, so a rule such as [A-Z]* matches hosts it used to miss.
  • A client-requested --compress-threads is capped at 8.

rsync-ssl now verifies the server certificate. The default openssl backend additionally binds it to the requested hostname, so a certificate valid for some other name is now rejected. The stunnel and gnutls backends refuse to run unless RSYNC_SSL_CA_CERT is set, or RSYNC_SSL_ALLOW_INSECURE_STUNNEL=1 / RSYNC_SSL_ALLOW_INSECURE_GNUTLS=1 is set to opt out.

-- Samuel Henrique [email protected] Tue, 15 Sep 2026 18:46:30 -0700

Discussion 1 comments · 12 points · janus · 10h
Open on Lobsters
Loading the discussion…

Domain filters

Stories from these domains are hidden from every list. Subdomains match too: blocking substack.com also hides danluu.substack.com. The list is kept in this browser only.

Help

Keyboard

j / k
Move down and up the story list. The arrow keys scroll whatever has focus.
Enter
Open the marked story in a window.
]
Open the next story in the list in place of the one in front. Back returns to it.
p
Pin or unpin the marked story, which keeps it in Pinned.
n / N
Move to the next or previous top-level comment in the window in front.
c
Collapse or expand that comment.
f
Hide or show the story list.
Esc
Close a menu or this help.
Access key m
Go to the menu bar. Most browsers take it with Alt on Windows and Linux, and Safari with Control and Option.
?
Show this help.

Windows

Each story opens in a window holding its article above its discussion; drag the bar between them to share the room differently. A window can be moved by its title bar, resized from any edge, snapped to a half or a corner by dragging it there, maximised, or minimised to the bar at the foot of the page. Open several stories to compare them, and switch between them from that bar. A window's Next story link reads on down the list in the same window.

A link in a comment or an article to another Hacker News or Lobsters thread opens that thread in a window too. A link to a single HN comment opens the comment above its replies.

While a story's window is in front, the Story and Discussion menus in the menu bar hold its commands: pinning, Next story, sorting, collapsing every thread, jumping to the first new comment. Each window also remembers where you were in its article and discussion, so a reload, or Back to a story that Next took you past, finds your place again. Closing a window forgets it.

The whole arrangement lives in the address, so a bookmark or a shared link brings it back, and Back undoes the last change. Moving between Hacker News, Lobsters, their lists, Pinned and Find changes only the list, and leaves the windows open.

The list

The pin at the start of a row keeps the story in Pinned, and the cross at its end hides it. Scroll past the end of the list to load more. Domain filters, in the View menu, hide every story from a site.

Find

Find takes any link and lists every time it was submitted to Hacker News and Lobsters, so you can read each discussion of it.

About

YAVCHN never sees your Hacker News or Lobsters login. The discussion is fetched from each site's public API; to vote or reply, follow the link above the discussion, or the arrow beside a comment, to the source's own site. Pins, hidden stories, filters and layout are kept in this browser only.

Open source: github.com/paulmooreparks/yavchn. Built with PUDL.