{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2026/cve-2026-70452-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-18T13:36:39Z",
      "generator": {
        "date": "2026-09-18T13:36:39Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-70452-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2026-08-13T15:19:00Z",
      "revision_history": [
        {
          "date": "2026-08-13T15:19:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-17T12:45:34Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-09-18T13:36:39Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-70452"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/rsync@3.2.3-4%2Bdeb11u4?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els3?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                "product": {
                  "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                  "product_id": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/rsync@3.2.3-4%2Bdeb11u4%2Btuxcare.els4?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64 as a component of Debian 11",
          "product_id": "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64"
        },
        "product_reference": "rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-70452",
      "cwe": {
        "id": "CWE-636",
        "name": "Not Failing Securely ('Failing Open')"
      },
      "notes": [
        {
          "category": "description",
          "text": "rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64",
          "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-70452"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-6692-28cx-wpqq",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-6692-28cx-wpqq"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-access-control-bypass-via-dns-resolution-failure",
          "url": "https://www.vulncheck.com/advisories/rsync-access-control-bypass-via-dns-resolution-failure"
        }
      ],
      "release_date": "2026-08-13T15:19:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-09T12:16:39.358164Z",
          "details": "This issue only applies when rsync runs as a standalone daemon (rsyncd) using hostname-based hosts allow/deny rules; deployments using rsync over SSH or IP/CIDR entries in those lists are not affected. Exploitation requires remotely inducing a DNS lookup failure at the exact moment the daemon evaluates the deny rule—a high‑complexity, timing‑dependent condition that does not impact availability and only risks module‑scoped data exposure or modification. Given these strict preconditions and the straightforward configuration patterns that inherently avoid the condition (IP literals/CIDR or SSH transport), this CVE is a low‑priority concern for centrally managed server and VM environments.",
          "product_ids": [
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els3.armel",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4+tuxcare.els4.armel",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.amd64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.arm64",
            "Debian-11:rsync-0:3.2.3-4+deb11u4.armel"
          ]
        }
      ]
    }
  ]
}