Major rsync upgrade in Debian because of 33 CVEs

Curated from Lobsters

When a core utility like rsync accumulates thirty-three vulnerabilities, the decision to jump major versions rather than backport patches signals a significant shift in maintenance strategy. For SREs, this isn't just a routine update; it’s a wake-up call regarding dependency rot in your base images. The maintainer’s choice to bump to 3.5.0 highlights that individual patching can become a security liability if the underlying codebase drifts too far from upstream. This approach reduces the attack surface by eliminating old, unpatched code paths entirely. However, it also introduces behavioral changes that may break existing automation. Your takeaway should be to immediately audit your rsync configurations for deprecated flags or changed default behaviors before applying this update in production, ensuring your backup scripts remain reliable under the new version.

apt-listchanges --which=both -f text --since=3.4.1+ds1-5+deb13u4 /var/cache/apt/archives/rsync_3.5.0+ds1-0+deb13u1_amd64.deb apt-listchanges: Reading changelogs... apt-listchanges: News rsync (3.5.0+ds1-0+deb13u1) trixie-security; urgency=medium In order to fix 33 CVEs, I have decided to bump the package to 3.5.0 rather than backporting all patches individually.

— Lobsters

Read the full article on Lobsters →