Hi Paul, The changelog of the latest rsync package available in stretch does say that these are fixed, but I can still see that stretch is shown as vulnerable on the security tracker.
https://security-tracker.debian.org/tracker/CVE-2016-9840 If these are fixed, could you please get the security tracker updated? Thanks & Regards Gunjan Gupta

