CVE-2024-12088Medium· 6.5▾ SunlitA flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vul…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.6%
4.6% → 4.7%
A flaw was found in rsync. When using the --safe-links option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
rsync <= 3.3.0discovery = 1.14openshift_container_platform = 4.0enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0enterprise_linux_eus = 9.6enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64_eus = 9.6_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_ibm_z_systems_eus = 9.6_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian_eus = 9.6_ppc64leenterprise_linux_server_aus = 9.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.6_ppc64leenterprise_linux_update_services_for_sap_solutions = 9.6arch_linuxlinuxnixos < 24.11suse_linuxsmartos < 20250123almalinux = 8.0almalinux = 9.0almalinux = 10.0Upgrade past the affected range:
nixos 24.11smartos 20250123Connected by shared product, vendor, weakness, or advisory.
CVE-2024-12087Medium· 6.5A path traversal vulnerability exists in rsync
CVE-2024-12084Critical· 9.8A heap-based buffer overflow flaw was found in the rsync daemon
CVE-2024-12086Medium· 6.1A flaw was found in rsync
CVE-2024-12085High· 7.5A flaw was found in rsync which could be triggered when rsync compares file checksums
CVE-2026-43618High· 8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receive…
CVE-2026-29518High· 7.0Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…