CVE-2024-12747
published 2025-01-14CVE-2024-12747: A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when…
PriorityP427medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.38%
29.9th percentile
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rsync | < rsync 3.2.7-1+deb12u1 (bookworm) | rsync 3.2.7-1+deb12u1 (bookworm) |
| msrc | azl3_rsync_3.2.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rsync_3.4.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_rsync_3.2.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_rsync_3.4.1-1_on_cbl_mariner_2.0 | — | — |
| samba | rsync | >= 0 < 3.2.3-4+deb11u2 | 3.2.3-4+deb11u2 |
| samba | rsync | >= 0 < 3.2.7-1+deb12u1 | 3.2.7-1+deb12u1 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
| samba | rsync | >= 0 < 3.3.0+ds1-3 | 3.3.0+ds1-3 |
| samba | rsync | >= 0 < 3.1.3-8ubuntu0.9 | 3.1.3-8ubuntu0.9 |
| samba | rsync | >= 0 < 3.1.3-8ubuntu0.8 | 3.1.3-8ubuntu0.8 |
| samba | rsync | >= 0 < 3.2.7-0ubuntu0.22.04.4 | 3.2.7-0ubuntu0.22.04.4 |
| samba | rsync | >= 0 < 3.2.7-0ubuntu0.22.04.3 | 3.2.7-0ubuntu0.22.04.3 |
| samba | rsync | >= 0 < 3.2.7-1ubuntu1.2 | 3.2.7-1ubuntu1.2 |
| samba | rsync | >= 0 < 3.2.7-1ubuntu1.1 | 3.2.7-1ubuntu1.1 |
| samba | rsync | >= 0 < 3.3.0-1ubuntu0.2 | 3.3.0-1ubuntu0.2 |
| samba | rsync | >= 0 < 3.3.0-1ubuntu0.1 | 3.3.0-1ubuntu0.1 |
| samba | rsync | >= 0 < 3.1.0-2ubuntu0.4+esm2 | 3.1.0-2ubuntu0.4+esm2 |
| samba | rsync | >= 0 < 3.1.0-2ubuntu0.4+esm1 | 3.1.0-2ubuntu0.4+esm1 |
| samba | rsync | >= 0 < 3.1.1-3ubuntu1.3+esm4 | 3.1.1-3ubuntu1.3+esm4 |
| samba | rsync | >= 0 < 3.1.1-3ubuntu1.3+esm3 | 3.1.1-3ubuntu1.3+esm3 |
| samba | rsync | >= 0 < 3.1.2-2.1ubuntu1.6+esm2 | 3.1.2-2.1ubuntu1.6+esm2 |
| samba | rsync | >= 0 < 3.1.2-2.1ubuntu1.6+esm1 | 3.1.2-2.1ubuntu1.6+esm1 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.6MEDIUM
vendor_msrc5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync regression
vendor_ubuntu·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-3 caused some regression in rsync.
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-28·CVSS 9.8
CVE-2024-12087 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to exp
Ubuntu
rsync regression
vendor_ubuntu·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
Title: rsync regression
Summary: USN-7206-1 caused some regression in rsync.
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use
Red Hat
rsync: Race Condition in rsync Handling Symbolic Links
vendor_redhat·2025-01-14·CVSS 5.6
CVE-2024-12747 [MEDIUM] CWE-362 rsync: Race Condition in rsync Handling Symbolic Links
rsync: Race Condition in rsync Handling Symbolic Links
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link a
Microsoft
Rsync: race condition in rsync handling symbolic links
vendor_msrc·2025-01-14·CVSS 5.6
CVE-2024-12747 [MEDIUM] CWE-362 Rsync: race condition in rsync handling symbolic links
Rsync: race condition in rsync handling symbolic links
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lear
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2025-01-14·CVSS 9.8
CVE-2024-12085 [CRITICAL] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacke
Debian
CVE-2024-12747: rsync - A flaw was found in rsync. This vulnerability arises from a race condition durin...
vendor_debian·2024·CVSS 5.6
CVE-2024-12747 [MEDIUM] CVE-2024-12747: rsync - A flaw was found in rsync. This vulnerability arises from a race condition durin...
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
Scope: local
bookworm: resolved (fixed in 3.2.7-1+deb12u1)
bullseye: resolved (fixed in 3.2.3-4+deb11u2)
forky: resolved (fixed in 3.3.0+ds1-3)
sid: resolved (fixed in 3.3.0+ds1-3)
trixie: resolved (fixed in 3.3.0+ds1-3)
OSV
rsync regression
osv·2025-02-10·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-3 fixed vulnerabilities in rsync for Ubuntu 24.10. The update
introduced a regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-
OSV
rsync vulnerabilities
osv·2025-01-28·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync vulnerabilities
rsync vulnerabilities
USN-7206-1 fixed vulnerabilities in Ubuntu 14.04 LTS to Ubuntu 24.04 LTS.
This update provides the corresponding updates for Ubuntu 24.10.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell,
OSV
rsync regression
osv·2025-01-16·CVSS 9.8
CVE-2024-12084 [CRITICAL] rsync regression
rsync regression
USN-7206-1 fixed vulnerabilities in rsync. The update introduced a
regression in rsync. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simo
GHSA
GHSA-gp7r-m4cc-qhwq: A flaw was found in rsync
ghsa_unreviewed·2025-01-14
CVE-2024-12747 [MEDIUM] CWE-362 GHSA-gp7r-m4cc-qhwq: A flaw was found in rsync
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
OSV
CVE-2024-12747: A flaw was found in rsync
osv·2025-01-14·CVSS 5.6
CVE-2024-12747 [MEDIUM] CVE-2024-12747: A flaw was found in rsync
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.
OSV
Several security issues were fixed in rsync
osv·2025-01-14·CVSS 9.8
CVE-2024-12084 [CRITICAL] Several security issues were fixed in rsync
Several security issues were fixed in rsync
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
did not properly handle checksum lengths. An attacker could use this
issue to execute arbitrary code. (CVE-2024-12084)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
compared checksums with uninitialized memory. An attacker could exploit
this issue to leak sensitive information. (CVE-2024-12085)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
incorrectly handled file checksums. A malicious server could use this
to expose arbitrary client files. (CVE-2024-12086)
Simon Scannell, Pedro Gallegos, and Jasiel Spelman discovered that rsync
mishandled symlinks for some settings. An attacker could exploit this
to write files outs
No detection rules found.
No public exploits indexed.
Bleepingcomputer
QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
blogs_bleepingcomputer·2025-01-23·CVSS 9.8
[CRITICAL] QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
## Sergiu Gatlan
QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices.
Rsync is an open-source file synchronization tool that supports direct file syncing via its daemon, SSH transfers via SSH, and incremental transfers that save time and bandwidth.
It's widely used by many backup solutions like Rclone, DeltaCopy, and ChronoSync, as well as in cloud and server management operations and public file distribution.
The flaws are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leak via uninitialized stack), CVE-2024-12086 (server leaks arbitrary client files), CVE-2024-12087 (path traversal via --inc-re
Bleepingcomputer
Over 660,000 Rsync servers exposed to code execution attacks
blogs_bleepingcomputer·2025-01-15·CVSS 9.8
[CRITICAL] Over 660,000 Rsync servers exposed to code execution attacks
## Over 660,000 Rsync servers exposed to code execution attacks
## Bill Toulas
The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations.
The Rsync flaws were discovered by Google Cloud and independent security researchers and can be combined to create powerful exploitation chains that lead to remote system compromise.
"In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on," reads the bulletin published on Openwall .
The six flaws are summarized below:
Heap Buffer Overflow (CVE-2024-12084) : Vulnerability arising from improper handling of checksum l
Bugzilla
CVE-2024-12747 rsync: Race Condition in rsync Handling Symbolic Links
bugzilla·2024-12-18·CVSS 5.6
CVE-2024-12747 [MEDIUM] CVE-2024-12747 rsync: Race Condition in rsync Handling Symbolic Links
CVE-2024-12747 rsync: Race Condition in rsync Handling Symbolic Links
This vulnerability stems from a race condition in rsync's handling of symbolic links. By exploiting timing differences, an attacker can bypass the expected behavior of skipping symbolic links during file synchronization. This flaw becomes critical in scenarios where rsync runs with elevated privileges, as it can inadvertently expose sensitive files to unprivileged users, potentially leading to privilege escalation.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2600 https://access.redhat.com/errata/RHSA-2025:2600
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:7050 https://access.redhat.com/errata
https://access.redhat.com/errata/RHBA-2025:6470https://access.redhat.com/errata/RHSA-2025:2600https://access.redhat.com/errata/RHSA-2025:7050https://access.redhat.com/errata/RHSA-2025:8385https://access.redhat.com/security/cve/CVE-2024-12747https://bugzilla.redhat.com/show_bug.cgi?id=2332968https://kb.cert.org/vuls/id/952657https://lists.debian.org/debian-lts-announce/2025/01/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20250131-0002/https://www.kb.cert.org/vuls/id/952657
2025-01-14
Published