CVE-2024-12087Medium· 6.5▾ SunlitA path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the clien…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
2.2% → 2.3%
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the --inc-recursive option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the --inc-recursive option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
rsync <= 3.3.0almalinux = 8.0almalinux = 9.0almalinux = 10.0arch_linuxlinuxnixos < 24.11suse_linuxsmartos < 20250123enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux_eus = 9.6enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64_eus = 9.6_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_ibm_z_systems_eus = 9.6_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian_eus = 9.6_ppc64leenterprise_linux_server_aus = 9.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.6_ppc64leenterprise_linux_update_services_for_sap_solutions = 9.6Upgrade past the affected range:
nixos 24.11smartos 20250123Connected by shared product, vendor, weakness, or advisory.
CVE-2024-12088Medium· 6.5A flaw was found in rsync
CVE-2024-12084Critical· 9.8A heap-based buffer overflow flaw was found in the rsync daemon
CVE-2024-12086Medium· 6.1A flaw was found in rsync
CVE-2024-12085High· 7.5A flaw was found in rsync which could be triggered when rsync compares file checksums
CVE-2026-43618High· 8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…
CVE-2026-29518High· 7.0Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…