CVE-2024-12084Critical· 9.8▾ AbyssalPoC availableA heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attac…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 14.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
72%
3 GitHub repos
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
rsync = 3.2.7rsync = 3.3.0almalinux = 10.0arch_linuxlinuxnixos < 24.11nixos = 24.11suse_linuxsmartos < 20250123enterprise_linux = 10.0Upgrade past the affected range:
nixos 24.11smartos 20250123Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-12085High· 7.5A flaw was found in rsync which could be triggered when rsync compares file checksums
CVE-2024-12088Medium· 6.5A flaw was found in rsync
CVE-2024-12087Medium· 6.5A path traversal vulnerability exists in rsync
CVE-2024-12086Medium· 6.1A flaw was found in rsync
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2025-25249High· 8.1A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…