Database/Control plane, storage & DevOps
rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinks
Impact
When rclone copies from an untrusted remote with --links, it recreates symlinks without validating the target, so a malicious remote plants a link that makes rclone write outside the destination directory. On a data-ingest node that is arbitrary file write as the mover's user - enough to drop a file into a systemd unit or an authorized_keys path.
Who can reach it
Anyone who controls content on a remote that your rclone job syncs down with --links enabled. In a GPU cluster that includes tenant-writable buckets used as ingest sources.
What to do
Upgrade rclone to the fixed release. Drop --links from jobs that pull from any source a tenant can write to, and run ingest jobs as an unprivileged user in a directory that contains nothing security-relevant.
References
Related entries
- Jenkins Script Security Plugin: Groovy sandbox escape via AST annotation extensions memberCVE-2026-57281 · Jenkins Script Security Plugin (Groovy sandbox, AST transformation annotations)High
- Airflow Backfill API: any Dag editor can read and cancel backfills belonging to other DagsCVE-2026-68968 · Apache Airflow Backfill API (authorization dependency id parsing)High
- GitLab CE/EE: improper input validation lets an unauthenticated user cause a denial of serviceCVE-2026-7427 · GitLab CE/EE (unauthenticated request path, improper input validation)High
- Splunk Enterprise Edge Processor sidecar: Prometheus metrics endpoint served without authenticationCVE-2026-76262 · Splunk Enterprise Edge Processor SPL2 Preview sidecar (Prometheus metrics endpoint)High
- Dell OpenManage Server Administrator (network-facing management service): OMSA is the in-band hardware management agentCVE-2026-81438 · Dell OpenManage Server Administrator (network-facing management service)High
- Linux kernel nfsd: uncapped POSIX ACL entry count drives an O(n^2) sort in the NFS serverCVE-2026-89695 · Linux kernel nfsd (NFSv4 POSIX ACL decoder, sort_pacl_range)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.