This bug was fixed in the package rclone - 1.69.3+dfsg-3ubuntu1

---------------
rclone (1.69.3+dfsg-3ubuntu1) stonking; urgency=medium

  * SECURITY UPDATE: authentication bypass in rcd leading to sensitive
    operations and/or remote command execution (LP: #2152913)
    - debian/patches/CVE-2026-41176.patch
    - debian/patches/CVE-2026-41176-2.patch
    - CVE-2026-41176
  * SECUIRTY UPDATE: unauthenticated remote command execution in rcd
    (LP: #2152914)
    - debian/patches/CVE-2026-41179.patch
    - CVE-2026-41179
  * SECURITY UPDATE: unauthenticated remote command execution in rcd
    (LP: #2160382)
    - d/p/CVE-2026-49980.patch: Disable unauthenticated inline remotes
    - CVE-2026-49980

 -- Wesley Hershberger <[email protected]>  Tue, 11 Aug
2026 09:50:08 -0500

** Changed in: rclone (Ubuntu Stonking)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-49980

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2152914

Title:
  CVE-2026-41179

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rclone/+bug/2152914/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to