ALAS2023-2026-1801


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1801
Advisory Released Date: 2026-06-08
Advisory Updated Date: 2026-06-08
Severity: Important

Issue Overview:

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation. (CVE-2026-43618)


Affected Packages:

rsync


Issue Correction:
Run dnf update rsync --releasever 2023.12.20260608 or dnf update --advisory ALAS2023-2026-1801 --releasever 2023.12.20260608 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    rsync-debugsource-3.4.0-1.amzn2023.0.4.aarch64
    rsync-debuginfo-3.4.0-1.amzn2023.0.4.aarch64
    rsync-3.4.0-1.amzn2023.0.4.aarch64

noarch:
    rsync-daemon-3.4.0-1.amzn2023.0.4.noarch

src:
    rsync-3.4.0-1.amzn2023.0.4.src

x86_64:
    rsync-debuginfo-3.4.0-1.amzn2023.0.4.x86_64
    rsync-debugsource-3.4.0-1.amzn2023.0.4.x86_64
    rsync-3.4.0-1.amzn2023.0.4.x86_64