CVE-2024-12086

Name
CVE-2024-12086
Description
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2024-12086
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2330577
secalert@redhat.com https://kb.cert.org/vuls/id/952657
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20250131-0002/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html
af854a3a-2127-422b-91ae-364da2661108 https://www.kb.cert.org/vuls/id/952657
secalert@redhat.com https://access.redhat.com/errata/RHBA-2025:6470
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:19368
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:20603
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:29197

Match rules

CPE URI Source package Min version Max version
shopxo >= 0 <= 3.3.0
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* rsync >= None <= 3.3.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
rsync edge-main 3.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
rsync edge-main 3.3.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.2.4-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.2.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.2.3-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.2.3-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.2.3-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync edge-main 3.1.2-r7 None possibly vulnerable
rsync 3.22-main 3.4.0-r0 None fixed
rsync 3.22-main 3.2.4-r2 None possibly vulnerable
rsync 3.22-main 3.1.2-r7 None possibly vulnerable
rsync 3.21-main 3.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
rsync 3.21-main 3.3.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync 3.21-main 3.3.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync 3.21-main 3.2.4-r2 None possibly vulnerable
rsync 3.21-main 3.1.2-r7 None possibly vulnerable
rsync 3.20-main 3.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
rsync 3.20-main 3.3.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync 3.20-main 3.2.4-r2 None possibly vulnerable
rsync 3.20-main 3.1.2-r7 None possibly vulnerable
rsync 3.19-main 3.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
rsync 3.19-main 3.2.7-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
rsync 3.19-main 3.2.4-r2 None possibly vulnerable
rsync 3.19-main 3.1.2-r7 None possibly vulnerable
rsync 3.18-main 3.4.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed