CVE-2024-12087
published 2025-01-14CVE-2024-12087: A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.26%
81.0th percentile
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| almalinux | almalinux | — | — |
| almalinux | almalinux | — | — |
| almalinux | almalinux | — | — |
| debian | rsync | < rsync 3.2.7-1+deb12u1 (bookworm) | rsync 3.2.7-1+deb12u1 (bookworm) |
| nixos | nixos | < 24.11 | 24.11 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_update_services_for_sap_solutions | — | — |
| samba | rsync | <= 3.3.0 | — |
| samba | rsync | >= 0 < 3.2.3-4+deb11u2 | 3.2.3-4+deb11u2 |
| samba | rsync | >= 0 < 3.2.7-1+deb12u1 | 3.2.7-1+deb12u1 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-3 caused some regression in rsync.
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-28·CVSS 9.8
CVE-2024-12087 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to exp
Ubuntu
rsync regression
vendor_ubuntu·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-1 caused some regression in rsync.
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-14·CVSS 9.8
CVE-2024-12085 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacke
Red Hat
rsync: Path traversal vulnerability in rsync
vendor_redhat·2025-01-14·CVSS 6.5
CVE-2024-12087 [MEDIUM] CWE-22 rsync: Path traversal vulnerability in rsync
rsync: Path traversal vulnerability in rsync
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client
Debian
CVE-2024-12087: rsync - A path traversal vulnerability exists in rsync. It stems from behavior enabled b...
vendor_debian·2024·CVSS 6.5
CVE-2024-12087 [MEDIUM] CVE-2024-12087: rsync - A path traversal vulnerability exists in rsync. It stems from behavior enabled b...
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
Scope: local
bookworm: resolved (fixed in 3.2.7-1+deb12u1)
bullseye: resolved (fixed in 3.2.3-4+deb11u2)
forky: resolved (fixed in 3.3.0+ds1-3)
sid: resolved (fixed in 3.3.0+ds1-3)
trixie: resolved (
OSV
rsync regression
osv·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-
OSV
rsync vulnerabilities
osv·2025-01-28·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync vulnerabilities
rsync vulnerabilities
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell,
OSV
rsync regression
osv·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simo
OSV
Several security issues were fixed in rsync
osv·2025-01-14·CVSS 9.8
CVE-2024-12084 [CRITICAL] Several security issues were fixed in rsync
Several security issues were fixed in rsync
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacker could exploit this
to write files outs
OSV
CVE-2024-12087: A path traversal vulnerability exists in rsync
osv·2025-01-14·CVSS 7.5
CVE-2024-12087 [HIGH] CVE-2024-12087: A path traversal vulnerability exists in rsync
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
GHSA
GHSA-9x68-7qq6-v523: A path traversal vulnerability exists in rsync
ghsa_unreviewed·2025-01-14
CVE-2024-12087 [MEDIUM] CWE-22 GHSA-9x68-7qq6-v523: A path traversal vulnerability exists in rsync
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-12087 rsync: Path traversal vulnerability in rsync
bugzilla·2024-12-05·CVSS 7.5
CVE-2024-12087 [HIGH] CVE-2024-12087 rsync: Path traversal vulnerability in rsync
CVE-2024-12087 rsync: Path traversal vulnerability in rsync
When the syncing of symbolic links is enabled, either through the -l or -a (--archive) flags, a malicious server can make the client write arbitrary files outside of the destination directory.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2600 https://access.redhat.com/errata/RHSA-2025:2600
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:7050 https://access.redhat.com/errata/RHSA-2025:7050
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2025:23154 https://access.redhat.com/errata/RHSA-2025:23154
---
This issue has been address
Bleepingcomputer
QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
blogs_bleepingcomputer·2025-01-23·CVSS 9.8
[CRITICAL] QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## Sergiu Gatlan
QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices.
Rsync is an open-source file synchronization tool that supports direct file syncing via its daemon, SSH transfers via SSH, and incremental transfers that save time and bandwidth.
It's widely used by many backup solutions like Rclone, DeltaCopy, and ChronoSync, as well as in cloud and server management operations and public file distribution.
The flaws are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leak via uninitialized stack), CVE-2024-12086 (server leaks arbitrary client files), CVE-2024-12087 (path traversal via --inc-re
Bleepingcomputer
Over 660,000 Rsync servers exposed to code execution attacks
blogs_bleepingcomputer·2025-01-15·CVSS 9.8
[CRITICAL] Over 660,000 Rsync servers exposed to code execution attacks
## Over 660,000 Rsync servers exposed to code execution attacks
## Bill Toulas
The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations.
The Rsync flaws were discovered by Google Cloud and independent security researchers and can be combined to create powerful exploitation chains that lead to remote system compromise.
"In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on," reads the bulletin published on Openwall .
The six flaws are summarized below:
Heap Buffer Overflow (CVE-2024-12084) : Vulnerability arising from improper handling of checksum l
https://access.redhat.com/errata/RHBA-2025:6470https://access.redhat.com/errata/RHSA-2025:23154https://access.redhat.com/errata/RHSA-2025:23235https://access.redhat.com/errata/RHSA-2025:23407https://access.redhat.com/errata/RHSA-2025:23415https://access.redhat.com/errata/RHSA-2025:23416https://access.redhat.com/errata/RHSA-2025:23842https://access.redhat.com/errata/RHSA-2025:23853https://access.redhat.com/errata/RHSA-2025:23854https://access.redhat.com/errata/RHSA-2025:23858https://access.redhat.com/errata/RHSA-2025:2600https://access.redhat.com/errata/RHSA-2025:7050https://access.redhat.com/errata/RHSA-2025:8385https://access.redhat.com/security/cve/CVE-2024-12087https://bugzilla.redhat.com/show_bug.cgi?id=2330672https://kb.cert.org/vuls/id/952657https://lists.debian.org/debian-lts-announce/2025/01/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20250131-0002/https://www.kb.cert.org/vuls/id/952657https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
2025-01-14
Published