安全公告详情

NS-SA-2026-0113

2026-09-07 18:00:00

简介

important: rsync/libarchive security update

严重级别

important

主题

An update for rsync/libarchive is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

rsync:
libarchive:


Security Fix(es):
rsync: An out of bounds read flaw has been discovered in rsync. A malicious client acting as the receiver of an rsync file transfer can trigger an OOB read via a negative array index. The rsync client requires at least read access to the remote rsync module to trigger the issue.(CVE-2025-10158)
rsync: bugfix
libarchive: A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.(CVE-2025-5914)
libarchive: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • rsync
  • libarchive

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["rsync-daemon-3.4.1-1.zncgsl7.2.noarch.rpm","rsync-3.4.1-1.zncgsl7.2.x86_64.rpm","rsync-doc-3.4.1-1.zncgsl7.2.noarch.rpm"],"source":"rsync-3.4.1-1.zncgsl7.2.src.rpm"},{"binary":["libarchive-3.7.1-1.zncgsl7.11.x86_64.rpm","libarchive-static-3.7.1-1.zncgsl7.11.x86_64.rpm","libarchive-doc-3.7.1-1.zncgsl7.11.noarch.rpm","libarchive-devel-3.7.1-1.zncgsl7.11.x86_64.rpm","libarchive-core-3.7.1-1.zncgsl7.11.x86_64.rpm","bsdcpio-3.7.1-1.zncgsl7.11.x86_64.rpm","bsdunzip-3.7.1-1.zncgsl7.11.x86_64.rpm","bsdtar-3.7.1-1.zncgsl7.11.x86_64.rpm","bsdcat-3.7.1-1.zncgsl7.11.x86_64.rpm"],"source":"libarchive-3.7.1-1.zncgsl7.11.src.rpm"}]}]}

CVE

参考