CVE-2026-53796: Rsync Toctou Path Resolution Bypass

Incomplete daemon/chroot check allows TOCTOU symlink race conditions during file operations. Ensure secure path resolution is active for all non-chrooted receiver transfers.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-53796-rsync-toctou-path-resolution-bypass --engine opengrep

Description

Incomplete daemon/chroot check allows TOCTOU symlink race conditions during file operations. Ensure secure path resolution is active for all non-chrooted receiver transfers.