CVE detail
CVE-2026-29518
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- CVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File WriteMicrosoft MSRC
Information published.
vendormsrc.microsoft.comMay 21, 2026, 8:02 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29518.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 20, 2026, 1:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2469055bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 20, 2026, 1:16 PM - https://access.redhat.com/security/cve/CVE-2026-29518access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:29197access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:26410access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:26408access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 1:16 PM - https://access.redhat.com/errata/RHSA-2026:26332access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 1:16 PM - https://www.vulncheck.com/advisories/rsync-toctou-race-condition-allows-symlink-based-arbitrary-file-writewww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comMay 20, 2026, 1:16 PM - https://michael.stapelberg.ch/posts/2026-05-24-minimal-memory-safe-go-rsync-vulns/michael.stapelberg.ch
No excerpt available.
referencemichael.stapelberg.chMay 20, 2026, 1:16 PM No excerpt available.
Exploitgithub.comMay 20, 2026, 1:16 PM- https://github.com/RsyncProject/rsync/pull/895/changes/8471fdd1561049ef5f58df44a1811a50bd9a531dgithub.com
No excerpt available.
Exploitgithub.comMay 20, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-43619CVSS 7.2 · High
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, lin…
- CVE-2026-62428CVSS 7.8 · High
When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For all copy operations the refer…
- CVE-2026-59676CVSS 5.8 · Medium
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux…
- CVE-2026-65598CVSS 8.9 · High
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping…
- CVE-2026-16082CVSS 1.9 · Low
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation…
- CVE-2026-54242CVSS 4.9 · Medium
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php an…