On Fri Jul 24, 2026 at 6:39 AM CEST, Ashishkumar Parmar X (asparmar - E 
INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Ashishkumar Parmar <[email protected]>
>
> This patch backports the upstream rsync v3.4.3 security fix train for
> CVE-2026-29518. The direct CVE fixes are [3] and [4]:
>
> - [3] enables secure_relative_open() for daemon modules running with
>   "use chroot = no", closing the receiver-side basis-file TOCTOU.
> - [4] routes the sender read path through secure_relative_open() from
>   the trusted module root, closing the matching sender-side TOCTOU.
>
> This patch also carries [1] and [2] from the same upstream v3.4.3
> security/update train. These are supporting secure_relative_open()
> changes, not standalone direct CVE fixes: [1] uses Linux
> openat2(RESOLVE_BENEATH) to preserve the same confinement while allowing
> legitimate in-tree symlinks, fixing upstream issue #715; [2] adds the
> equivalent FreeBSD/macOS O_RESOLVE_BENEATH path. Debian's
> rsync 3.4.1+ds1-5+deb13u3 security update also carries these commits
> before the direct CVE-2026-29518 commits.
>
> The upstream fixed release is referenced in [5], and the public CVE
> record is referenced in [6]. Individual backported commit links are
> also recorded in the embedded patch headers.
>
> [1] 
> https://github.com/RsyncProject/rsync/commit/4fa7156ccdb2ad34b034d18fe2fd6cd79adef8a1
> [2] 
> https://github.com/RsyncProject/rsync/commit/7f60ec001a0be63b770707ec8b829524c3809a43
> [3] 
> https://github.com/RsyncProject/rsync/commit/f1c24ab03bc85cb2638a569faa60216582fb6c5d
> [4] 
> https://github.com/RsyncProject/rsync/commit/859d44fa4f1420775e4ba050337ef32092f2894c
> [5] https://github.com/RsyncProject/rsync/releases/tag/v3.4.3
> [6] https://www.cve.org/CVERecord?id=CVE-2026-29518
>
> Signed-off-by: Ashishkumar Parmar <[email protected]>
> ---
> Changes in v2:
> - No changes made; rebase only.
>
>  .../rsync/files/CVE-2026-29518_p1.patch       | 392 ++++++++++++++++++
>  .../rsync/files/CVE-2026-29518_p2.patch       |  98 +++++
>  .../rsync/files/CVE-2026-29518_p3.patch       | 328 +++++++++++++++
>  .../rsync/files/CVE-2026-29518_p4.patch       |  71 ++++
>  meta/recipes-devtools/rsync/rsync_3.4.1.bb    |   4 +
>  5 files changed, 893 insertions(+)
>  create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p1.patch
>  create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p2.patch
>  create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p3.patch
>  create mode 100644 meta/recipes-devtools/rsync/files/CVE-2026-29518_p4.patch

Hello,

This series caused a build issue.
See: 
https://lore.kernel.org/openembedded-core/[email protected]/T/#mac8cd24d85cb37cd8fa468a51921ac376e238c7f

Regards,
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242193): 
https://lists.openembedded.org/g/openembedded-core/message/242193
Mute This Topic: https://lists.openembedded.org/mt/120421792/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Ashishkumar Parmar X (asparmar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
        • ... Yoann Congal via lists.openembedded.org

Reply via email to