{"id":"CVE-2024-12085","title":"A flaw was found in rsync which could be triggered when rsync compares file checksums","summary":"A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-908"],"vendor":"samba","product":"rsync","affected":["rsync < 3.3.0","openshift = 5.0","openshift_container_platform = 4.12","openshift_container_platform = 4.13","openshift_container_platform = 4.14","openshift_container_platform = 4.15","openshift_container_platform = 4.16","openshift_container_platform = 4.17","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux_eus = 8.8","enterprise_linux_eus = 9.2","enterprise_linux_eus = 9.4","enterprise_linux_eus = 9.6","enterprise_linux_for_arm_64 = 8.0_aarch64","enterprise_linux_for_arm_64 = 9.0_aarch64","enterprise_linux_for_arm_64 = 9.2_aarch64","enterprise_linux_for_arm_64_eus = 8.8_aarch64","enterprise_linux_for_arm_64_eus = 9.4_aarch64","enterprise_linux_for_arm_64_eus = 9.6_aarch64","enterprise_linux_for_ibm_z_systems = 8.0_s390x","enterprise_linux_for_ibm_z_systems = 9.0_s390x","enterprise_linux_for_ibm_z_systems = 9.2_s390x","enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x","enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x","enterprise_linux_for_ibm_z_systems_eus = 9.6_s390x","enterprise_linux_for_power_little_endian = 8.0_ppc64le","enterprise_linux_for_power_little_endian = 8.8_ppc64le","enterprise_linux_for_power_little_endian = 9.0_ppc64le","enterprise_linux_for_power_little_endian = 9.2_ppc64le","enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le","enterprise_linux_for_power_little_endian_eus = 9.6_ppc64le","enterprise_linux_server = 6.0","enterprise_linux_server = 7.0","enterprise_linux_server_aus = 8.2","enterprise_linux_server_aus = 8.4","enterprise_linux_server_aus = 8.6","enterprise_linux_server_aus = 9.2","enterprise_linux_server_aus = 9.4","enterprise_linux_server_aus = 9.6","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.0_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64le","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.6_ppc64le","enterprise_linux_server_tus = 8.4","enterprise_linux_server_tus = 8.6","enterprise_linux_server_tus = 8.8","enterprise_linux_update_services_for_sap_solutions = 8.4","enterprise_linux_update_services_for_sap_solutions = 8.6","enterprise_linux_update_services_for_sap_solutions = 9.0","enterprise_linux_update_services_for_sap_solutions = 9.2","enterprise_linux_update_services_for_sap_solutions = 9.6","almalinux = 8.0","almalinux = 9.0","almalinux = 10.0","arch_linux","linux","nixos < 24.11","suse_linux","smartos < 20250123"],"patched":["rsync 3.3.0","nixos 24.11","smartos 20250123"],"published":"2025-01-14","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:17:25.433","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-12085","references":[{"url":"https://access.redhat.com/errata/RHBA-2025:6470","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6122","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0324","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0325","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0637","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0688","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0714","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0774","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0787","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0790","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0849","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0884","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0885","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1120","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1123","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1128","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1225","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1227","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1242","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1451","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21885","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2701","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-12085","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2330539","label":"secalert@redhat.com"},{"url":"https://kb.cert.org/vuls/id/952657","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20250131-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.kb.cert.org/vuls/id/952657","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12085.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-12085"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12085"}],"tags":["nvd","exploit-available","csaf","vex","red-hat"],"epss":0.08823,"epssPercentile":0.95014,"exploits":{"github":1,"githubRepos":["https://github.com/Otsutez/cve-2024-12085"],"checkedAt":"2026-09-21T15:20:06.113Z"},"exploitAvailable":true,"ingestedAt":"2026-06-29T13:24:34.145Z","slug":"CVE-2024-12085","body":"## Overview\n\nA flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.\n\n## Affected\n\n- `rsync < 3.3.0`\n- `openshift = 5.0`\n- `openshift_container_platform = 4.12`\n- `openshift_container_platform = 4.13`\n- `openshift_container_platform = 4.14`\n- `openshift_container_platform = 4.15`\n- `openshift_container_platform = 4.16`\n- `openshift_container_platform = 4.17`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux_eus = 8.8`\n- `enterprise_linux_eus = 9.2`\n- `enterprise_linux_eus = 9.4`\n- `enterprise_linux_eus = 9.6`\n- `enterprise_linux_for_arm_64 = 8.0_aarch64`\n- `enterprise_linux_for_arm_64 = 9.0_aarch64`\n- `enterprise_linux_for_arm_64 = 9.2_aarch64`\n- `enterprise_linux_for_arm_64_eus = 8.8_aarch64`\n- `enterprise_linux_for_arm_64_eus = 9.4_aarch64`\n- `enterprise_linux_for_arm_64_eus = 9.6_aarch64`\n- `enterprise_linux_for_ibm_z_systems = 8.0_s390x`\n- `enterprise_linux_for_ibm_z_systems = 9.0_s390x`\n- `enterprise_linux_for_ibm_z_systems = 9.2_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x`\n- `enterprise_linux_for_ibm_z_systems_eus = 9.6_s390x`\n- `enterprise_linux_for_power_little_endian = 8.0_ppc64le`\n- `enterprise_linux_for_power_little_endian = 8.8_ppc64le`\n- `enterprise_linux_for_power_little_endian = 9.0_ppc64le`\n- `enterprise_linux_for_power_little_endian = 9.2_ppc64le`\n- `enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le`\n- `enterprise_linux_for_power_little_endian_eus = 9.6_ppc64le`\n- `enterprise_linux_server = 6.0`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_server_aus = 8.2`\n- `enterprise_linux_server_aus = 8.4`\n- `enterprise_linux_server_aus = 8.6`\n- `enterprise_linux_server_aus = 9.2`\n- `enterprise_linux_server_aus = 9.4`\n- `enterprise_linux_server_aus = 9.6`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.0_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64le`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.6_ppc64le`\n- `enterprise_linux_server_tus = 8.4`\n- `enterprise_linux_server_tus = 8.6`\n- `enterprise_linux_server_tus = 8.8`\n- `enterprise_linux_update_services_for_sap_solutions = 8.4`\n- `enterprise_linux_update_services_for_sap_solutions = 8.6`\n- `enterprise_linux_update_services_for_sap_solutions = 9.0`\n- `enterprise_linux_update_services_for_sap_solutions = 9.2`\n- `enterprise_linux_update_services_for_sap_solutions = 9.6`\n- `almalinux = 8.0`\n- `almalinux = 9.0`\n- `almalinux = 10.0`\n- `arch_linux`\n- `linux`\n- `nixos < 24.11`\n- `suse_linux`\n- `smartos < 20250123`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `rsync 3.3.0`\n- `nixos 24.11`\n- `smartos 20250123`\n\n## Vendor advisories\n\n- **RHSA-2025:0849** · Red Hat · fixed in: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION) · released 2025-01-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:0849)\n- **RHSA-2025:0714** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2025-01-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:0714)\n- **RHSA-2025:1242** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:1242)\n- **RHSA-2025:1225** · Red Hat · fixed in: RHOL 5.8 for RHEL 9 · released 2025-02-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:1225)\n- **RHSA-2025:1227** · Red Hat · fixed in: RHOL 5.9 for RHEL 9 · released 2025-02-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:1227)\n- **RHSA-2025:2701** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-03-20 · [advisory](https://access.redhat.com/errata/RHSA-2025:2701)\n- **RHSA-2025:1451** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-02-19 · [advisory](https://access.redhat.com/errata/RHSA-2025:1451)\n- **RHSA-2025:1128** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2025-02-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:1128)\n- **RHSA-2025:1123** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2025-02-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:1123)\n- **RHSA-2025:1120** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-02-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:1120)\n- **RHSA-2024:6122** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-02-25 · [advisory](https://access.redhat.com/errata/RHSA-2024:6122)\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12085.json)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":41.3,"likelihood":1.8,"exploitation":12,"ransomware":0},"changes":[{"seq":4766,"id":"CVE-2024-12085","ts":1788887205076,"field":"exploit_available","old":"false","new":"true"},{"seq":3649,"id":"CVE-2024-12085","ts":1788886321623,"field":"exploit_available","old":"true","new":"false"},{"seq":2500,"id":"CVE-2024-12085","ts":1788882989443,"field":"exploit_available","old":"false","new":"true"},{"seq":1529,"id":"CVE-2024-12085","ts":1788882403266,"field":"exploit_available","old":"true","new":"false"},{"seq":643,"id":"CVE-2024-12085","ts":1788881840515,"field":"exploit_available","old":"false","new":"true"}]}