CVE-2024-12085High· 7.5▾ MidnightPoC availableA flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 1.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
9.4%
1 GitHub repo
Last analysed / modified upstream
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
rsync < 3.3.0openshift = 5.0openshift_container_platform = 4.12openshift_container_platform = 4.13openshift_container_platform = 4.14openshift_container_platform = 4.15openshift_container_platform = 4.16openshift_container_platform = 4.17enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux_eus = 8.8enterprise_linux_eus = 9.2enterprise_linux_eus = 9.4enterprise_linux_eus = 9.6enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64 = 9.2_aarch64enterprise_linux_for_arm_64_eus = 8.8_aarch64enterprise_linux_for_arm_64_eus = 9.4_aarch64enterprise_linux_for_arm_64_eus = 9.6_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_ibm_z_systems = 9.2_s390xenterprise_linux_for_ibm_z_systems_eus = 8.8_s390xenterprise_linux_for_ibm_z_systems_eus = 9.4_s390xenterprise_linux_for_ibm_z_systems_eus = 9.6_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_power_little_endian = 8.8_ppc64leenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian = 9.2_ppc64leenterprise_linux_for_power_little_endian_eus = 9.4_ppc64leenterprise_linux_for_power_little_endian_eus = 9.6_ppc64leenterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_aus = 9.2enterprise_linux_server_aus = 9.4enterprise_linux_server_aus = 9.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.0_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.6_ppc64leenterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6enterprise_linux_server_tus = 8.8enterprise_linux_update_services_for_sap_solutions = 8.4enterprise_linux_update_services_for_sap_solutions = 8.6enterprise_linux_update_services_for_sap_solutions = 9.0enterprise_linux_update_services_for_sap_solutions = 9.2enterprise_linux_update_services_for_sap_solutions = 9.6almalinux = 8.0almalinux = 9.0almalinux = 10.0arch_linuxlinuxnixos < 24.11suse_linuxsmartos < 20250123Upgrade past the affected range:
rsync 3.3.0nixos 24.11smartos 20250123Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-12084Critical· 9.8A heap-based buffer overflow flaw was found in the rsync daemon
CVE-2024-12088Medium· 6.5A flaw was found in rsync
CVE-2024-12087Medium· 6.5A path traversal vulnerability exists in rsync
CVE-2024-12086Medium· 6.1A flaw was found in rsync
CVE-2026-91740Medium· 4.3Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
CVE-2026-91720Medium· 4.7Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page