Amazon Linux 2023 Security Advisory: ALAS2023-2026-1801
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. (CVE-2026-43618)
Affected Packages:
rsync
Issue Correction:
Run dnf update rsync --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1801 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
rsync-debugsource-3.4.0-1.amzn2023.0.4.aarch64
rsync-debuginfo-3.4.0-1.amzn2023.0.4.aarch64
rsync-3.4.0-1.amzn2023.0.4.aarch64
noarch:
rsync-daemon-3.4.0-1.amzn2023.0.4.noarch
src:
rsync-3.4.0-1.amzn2023.0.4.src
x86_64:
rsync-debuginfo-3.4.0-1.amzn2023.0.4.x86_64
rsync-debugsource-3.4.0-1.amzn2023.0.4.x86_64
rsync-3.4.0-1.amzn2023.0.4.x86_64