7.5

CVE-2024-12085

Exploit

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Data is provided by the National Vulnerability Database (NVD)
SambaRsync Version < 3.3.0
RedhatOpenshift Version5.0
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Eus Version8.8
RedhatEnterprise Linux Eus Version9.2
RedhatEnterprise Linux Eus Version9.4
RedhatEnterprise Linux Eus Version9.6
RedhatEnterprise Linux For Arm 64 Version8.0_aarch64
RedhatEnterprise Linux For Arm 64 Version9.0_aarch64
RedhatEnterprise Linux For Arm 64 Version9.2_aarch64
RedhatEnterprise Linux For Arm 64 Eus Version8.8_aarch64
RedhatEnterprise Linux For Arm 64 Eus Version9.4_aarch64
RedhatEnterprise Linux For Arm 64 Eus Version9.6_aarch64
AlmalinuxAlmalinux Version8.0 Update-
AlmalinuxAlmalinux Version9.0 Update-
AlmalinuxAlmalinux Version10.0 Update-
ArchlinuxArch Linux Version-
GentooLinux Version-
NixosNixos Version < 24.11
SuseSuse Linux Version-
TritondatacenterSmartos Version < 20250123
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.67% 0.926
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secalert@redhat.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://bugzilla.redhat.com/show_bug.cgi?id=2330539
Third Party Advisory
Issue Tracking