rsync (3.4.1+ds1-7)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/debian/rsync.git
-
- Branch: debian/master
- Path: debian/changelog
- Repo size: 4907008
- Browser: https://salsa.debian.org/debian/rsync
- Last scan: 2025-12-06 05:43:04+00
- Next scan: 2025-12-11 15:48:00+00
- CI pipeline status: failed
- Debian changelog in Git:
rsync (3.4.1+ds1-7) unstable; urgency=medium
* Team upload.
[ Arnaud Rebillout ]
* d/control: Switch back to python3-cmarkgfm for all architectures
[ Matheus Polkorny ]
* d/p/CVE-2025-10158.patch: Import upstream patch to fix CVE-2025-10158
A malicious client acting as the receiver of an rsync file transfer
can trigger an out of bounds read of a heap based buffer,
via a negative array index. (Closes: #1121442)
-- Matheus Polkorny <mpolkorny@gmail.com> Thu, 27 Nov 2025 21:01:55 -0300
- This branch is even with tag debian/3.4.1+ds1-7