Vulnerabilities in Unbound, Kata-Containers, BIND, PostgreSQL, HPLIP, MongoDB, Rsync, 7-zip, Yelp, qSnapper, and Suricata
Several recently identified critical vulnerabilities: Six vulnerabilities in the file synchronization utility rsync. The most dangerous issue (CVE-2026-29518), caused by a race condition when processing symbolic links, allows for privilege escalation when running rsync in background mode without chroot isolation. The attack is executed via replacing a file with a symbolic link pointing to an arbitrary file in the system at the moment […]
