CVE-2024-12084
published 2025-01-15CVE-2024-12084: A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| almalinux | almalinux | — | — |
| debian | rsync | < rsync 3.2.7-1+deb12u1 (bookworm) | rsync 3.2.7-1+deb12u1 (bookworm) |
| msrc | azl3_rsync_3.2.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rsync_3.4.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_rsync_3.2.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rsync_3.4.1-1_on_cbl_mariner_2.0 | — | — |
| nixos | nixos | < 24.11 | 24.11 |
| nixos | nixos | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| samba | rsync | — | — |
| samba | rsync | — | — |
| samba | rsync | >= 0 < 3.2.7-1+deb12u1 | 3.2.7-1+deb12u1 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
| samba | rsync | >= 0 < 3.1.3-8ubuntu0.9 | 3.1.3-8ubuntu0.9 |
| samba | rsync | >= 0 < 3.1.3-8ubuntu0.8 | 3.1.3-8ubuntu0.8 |
| samba | rsync | >= 0 < 3.2.7-0ubuntu0.22.04.4 | 3.2.7-0ubuntu0.22.04.4 |
| samba | rsync | >= 0 < 3.2.7-0ubuntu0.22.04.3 | 3.2.7-0ubuntu0.22.04.3 |
| samba | rsync | >= 0 < 3.2.7-1ubuntu1.2 | 3.2.7-1ubuntu1.2 |
| samba | rsync | >= 0 < 3.2.7-1ubuntu1.1 | 3.2.7-1ubuntu1.1 |
| samba | rsync | >= 0 < 3.3.0-1ubuntu0.2 | 3.3.0-1ubuntu0.2 |
| samba | rsync | >= 0 < 3.3.0-1ubuntu0.1 | 3.3.0-1ubuntu0.1 |
| samba | rsync | >= 0 < 3.1.0-2ubuntu0.4+esm2 | 3.1.0-2ubuntu0.4+esm2 |
| samba | rsync | >= 0 < 3.1.0-2ubuntu0.4+esm1 | 3.1.0-2ubuntu0.4+esm1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL