← back
CVE-2024-12084criticalCWE-122

Rsync: heap buffer overflow in rsync due to improper checksum length handling

70Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.8epss 72%
from disclosure to weapon6 days
Published on NVDJan 15
1st PoC+6d
exploitation probability
72%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
2 products (15 components)
Red Hat Enterprise Linux BaseOS (v. 10) · Red Hat Enterprise Linux AppStream (v. 10)
Not affected
5 products (12 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat OpenShift Container Platform 4
In short

Rsync has a critical flaw where an attacker can crash the service or potentially run malicious code by sending specially crafted data that overflows a buffer used for checksums. This happens because the program doesn't properly limit how much data it writes to memory.

Technical detail

A heap buffer overflow in rsync's checksum handling allows an attacker to write beyond the bounds of the sum2 buffer when MAX_DIGEST_LEN exceeds SUM_LENGTH (16 bytes). The vulnerability stems from improper validation of attacker-controlled s2length parameters, enabling remote code execution or denial of service against rsync daemon instances.

Summary generated and translated by AI from the official description.
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.