MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2024-12086

CVSS 6.1v3.1pub. 2025-01-14upd. 2026-06-30

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
  • Almalinux

    OS
    Almalinux
    10.08.09.0
  • Archlinux Arch Linux

    OS
    Archlinux
    all versions
  • Gentoo Linux

    OS
    Gentoo
    all versions
  • Nixos

    OS
    Nixos
    < 24.11
  • Red Hat Enterprise Linux

    OS
    Redhat
    10.06.07.08.09.0
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    4.0
  • Samba Rsync

    APP
    Samba
    ≤ 3.3.0
  • SUSE Linux

    OS
    Suse
    all versions
  • Tritondatacenter Smartos

    OS
    Tritondatacenter
    < 20250123
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)