Rsync 3.5.0 fixes 33 CVEs; LTS backports on the way
Andrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
Rsync 3.5.0 is out with fixes for 33 CVEs, a high-volume security drop for one of the most widely deployed file-transfer tools on Unix-like systems.
Andrew Tridgell announced the release and said backport patch sets for 3.2.7 and 3.4.1 went to distribution maintainers last week, so long-term support packages should pick up the same fixes shortly. Those older lines remain common in enterprise and LTS images, which is why the backports matter as much as the new point release itself.
Rsync underpins backups, mirrors, and deployment pipelines across servers and desktops. A cluster of unresolved flaws in both current and maintained older trees leaves a large install base exposed until operators upgrade or apply the distro updates. Full CVE notes ship with the 3.5.0 release documentation; operators should treat this as a priority security update rather than a routine feature bump.