Heap-based buffer overflow in Rsync - CVE-2024-12084

 

Heap-based buffer overflow in Rsync - CVE-2024-12084

Published: January 14, 2025 / Updated: January 31, 2025


Vulnerability identifier: #VU102729
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12084
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling checksum lengths (s2length). A remote attacker can send specially crafted packets to the daemon, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Rsync
APEX Cloud Platform for Red Hat OpenShift
Debian Linux
SUSE Linux Enterprise Server 15 SP6
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Arch Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
Ubuntu
Slackware Linux
Basesystem Module
openSUSE Leap
openEuler
Fedora
ArubaOS-CX (AOS-CX)
LANTIME Operating System Firmware (LTOS)
Dell EMC VxRail Appliance
AirWave Management Platform
Splunk Universal Forwarder
rsync (Ubuntu package)
rsync-debugsource
rsync-debuginfo
rsync
rsync (Debian package)
rsync-help
net-misc/rsync
APEX Cloud Platform for Microsoft Azure

How to mitigate CVE-2024-12084

Install updates from vendor's website.

Rsync - update to 3.4.0
ArubaOS-CX (AOS-CX) - addressed in versions 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
Dell EMC VxRail Appliance - update to 8.321
Splunk Universal Forwarder - addressed in versions 9.3.12, 9.4.11, 10.0.6, 10.2.3
rsync (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.3-8ubuntu0.8, 3.1.3-8ubuntu0.9, 3.2.7-0ubuntu0.22.04.3, 3.2.7-0ubuntu0.22.04.4, 3.2.7-1ubuntu1.1, 3.2.7-1ubuntu1.2, 3.3.0-1ubuntu0.1, 3.3.0-1ubuntu0.2
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
rsync-debugsource - addressed in versions 3.1.3-3.43.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1, 3.2.7-150600.3.21.1
rsync-debuginfo - addressed in versions 3.1.3-3.43.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1, 3.2.7-150600.3.21.1
rsync - addressed in versions 3.1.3-3.43.1, 3.2.3-150400.3.31.1, 3.2.7-7.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1, 3.2.7-150600.3.21.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
rsync (Debian package) - update to 3.2.7-1+deb12u1
rsync - update to 3.2.7-6
rsync-debuginfo - update to 3.2.7-6
rsync-debugsource - update to 3.2.7-6
rsync-help - update to 3.2.7-6
net-misc/rsync - update to 3.3.0-r2
rsync - update to 3.4.0
rsync - update to 3.4.0-1
rsync - addressed in versions 3.4.0-1.fc40, 3.4.0-1.fc41, 3.4.1-1.fc41
AirWave Management Platform - update to 8.3.0.5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins