CVE-2024-12085
published 2025-01-14CVE-2024-12085: A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
8.65%
94.5th percentile
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| almalinux | almalinux | — | — |
| almalinux | almalinux | — | — |
| almalinux | almalinux | — | — |
| debian | rsync | < rsync 3.2.7-1+deb12u1 (bookworm) | rsync 3.2.7-1+deb12u1 (bookworm) |
| msrc | azl3_rsync_3.2.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rsync_3.4.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_rsync_3.2.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rsync_3.4.1-1_on_cbl_mariner_2.0 | — | — |
| nixos | nixos | < 24.11 | 24.11 |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Ubuntu
rsync regression
vendor_ubuntu·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-3 caused some regression in rsync.
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-28·CVSS 9.8
CVE-2024-12087 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to exp
Ubuntu
rsync regression
vendor_ubuntu·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-1 caused some regression in rsync.
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use
Red Hat
rsync: Info Leak via Uninitialized Stack Contents
vendor_redhat·2025-01-14·CVSS 7.5
CVE-2024-12085 [HIGH] CWE-908 rsync: Info Leak via Uninitialized Stack Contents
rsync: Info Leak via Uninitialized Stack Contents
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
Statement: This vulnerability is rated as having Important impact as it helps bypass Address Space Layout Randomization (ASLR). ASLR is a memory protection system which makes the
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-14·CVSS 9.8
CVE-2024-12085 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacke
Microsoft
Rsync: info leak via uninitialized stack contents
vendor_msrc·2025-01-14·CVSS 7.5
CVE-2024-12085 [HIGH] CWE-908 Rsync: info leak via uninitialized stack contents
Rsync: info leak via uninitialized stack contents
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mic
Debian
CVE-2024-12085: rsync - A flaw was found in rsync which could be triggered when rsync compares file chec...
vendor_debian·2024·CVSS 7.5
CVE-2024-12085 [HIGH] CVE-2024-12085: rsync - A flaw was found in rsync which could be triggered when rsync compares file chec...
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
Scope: local
bookworm: resolved (fixed in 3.2.7-1+deb12u1)
bullseye: resolved (fixed in 3.2.3-4+deb11u2)
forky: resolved (fixed in 3.3.0+ds1-3)
sid: resolved (fixed in 3.3.0+ds1-3)
trixie: resolved (fixed in 3.3.0+ds1-3)
OSV
rsync regression
osv·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-
OSV
rsync vulnerabilities
osv·2025-01-28·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync vulnerabilities
rsync vulnerabilities
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell,
OSV
rsync regression
osv·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simo
GHSA
GHSA-xh5q-pch5-g3xq: A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums
ghsa_unreviewed·2025-01-14
CVE-2024-12085 [HIGH] CWE-119 GHSA-xh5q-pch5-g3xq: A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
OSV
CVE-2024-12085: A flaw was found in rsync which could be triggered when rsync compares file checksums
osv·2025-01-14·CVSS 7.5
CVE-2024-12085 [HIGH] CVE-2024-12085: A flaw was found in rsync which could be triggered when rsync compares file checksums
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
OSV
Several security issues were fixed in rsync
osv·2025-01-14·CVSS 9.8
CVE-2024-12084 [CRITICAL] Several security issues were fixed in rsync
Several security issues were fixed in rsync
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacker could exploit this
to write files outs
No detection rules found.
No public exploits indexed.
Bleepingcomputer
QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
blogs_bleepingcomputer·2025-01-23·CVSS 9.8
[CRITICAL] QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## Sergiu Gatlan
QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices.
Rsync is an open-source file synchronization tool that supports direct file syncing via its daemon, SSH transfers via SSH, and incremental transfers that save time and bandwidth.
It's widely used by many backup solutions like Rclone, DeltaCopy, and ChronoSync, as well as in cloud and server management operations and public file distribution.
The flaws are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leak via uninitialized stack), CVE-2024-12086 (server leaks arbitrary client files), CVE-2024-12087 (path traversal via --inc-re
Bleepingcomputer
Over 660,000 Rsync servers exposed to code execution attacks
blogs_bleepingcomputer·2025-01-15·CVSS 9.8
[CRITICAL] Over 660,000 Rsync servers exposed to code execution attacks
## Over 660,000 Rsync servers exposed to code execution attacks
## Bill Toulas
The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations.
The Rsync flaws were discovered by Google Cloud and independent security researchers and can be combined to create powerful exploitation chains that lead to remote system compromise.
"In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on," reads the bulletin published on Openwall .
The six flaws are summarized below:
Heap Buffer Overflow (CVE-2024-12084) : Vulnerability arising from improper handling of checksum l
Bugzilla
CVE-2024-12085 rsync: Info Leak via Uninitialized Stack Contents
bugzilla·2024-12-05·CVSS 7.5
CVE-2024-12085 [HIGH] CVE-2024-12085 rsync: Info Leak via Uninitialized Stack Contents
CVE-2024-12085 rsync: Info Leak via Uninitialized Stack Contents
The attacker can exploit this vulnerability to leak uninitialized stack data byte by byte, potentially exposing memory locations of critical data.It uses a buffer (sum2) on the stack to store part of the checksum but does not initialize this buffer. An attacker can manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory. This allows an attacker to leak one byte of uninitialized stack data at a time. Over multiple requests, the attacker can leak up to MAX_DIGEST_LEN - 8 bytes of sensitive data, which could help defeat Address Space Layout Randomization (ASLR).
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:03
https://access.redhat.com/errata/RHBA-2025:6470https://access.redhat.com/errata/RHSA-2025:0324https://access.redhat.com/errata/RHSA-2025:0325https://access.redhat.com/errata/RHSA-2025:0637https://access.redhat.com/errata/RHSA-2025:0688https://access.redhat.com/errata/RHSA-2025:0714https://access.redhat.com/errata/RHSA-2025:0774https://access.redhat.com/errata/RHSA-2025:0787https://access.redhat.com/errata/RHSA-2025:0790https://access.redhat.com/errata/RHSA-2025:0849https://access.redhat.com/errata/RHSA-2025:0884https://access.redhat.com/errata/RHSA-2025:0885https://access.redhat.com/errata/RHSA-2025:1120https://access.redhat.com/errata/RHSA-2025:1123https://access.redhat.com/errata/RHSA-2025:1128https://access.redhat.com/errata/RHSA-2025:1225https://access.redhat.com/errata/RHSA-2025:1227https://access.redhat.com/errata/RHSA-2025:1242https://access.redhat.com/errata/RHSA-2025:1451https://access.redhat.com/errata/RHSA-2025:21885https://access.redhat.com/errata/RHSA-2025:2701https://access.redhat.com/security/cve/CVE-2024-12085https://bugzilla.redhat.com/show_bug.cgi?id=2330539https://kb.cert.org/vuls/id/952657https://lists.debian.org/debian-lts-announce/2025/01/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20250131-0002/https://www.kb.cert.org/vuls/id/952657https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
2025-01-14
Published