Information disclosure in Rsync - CVE-2024-12086
Published: January 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when handling checksums. A remote attacker can trick the victim into connecting to an attacker-controlled server and enumerate contents of arbitrary files on the client's machine, basically allowing a rouge server to read contents byte-by-byte of any file on the client's system.
This issue occurs when files are being copied from a client to a server.
Affected software
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Gentoo Linux
SUSE Linux Enterprise Desktop 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15 SP5
Arch Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Ubuntu
Slackware Linux
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
Fedora
PowerStore 1000T
PowerStore 500T
PowerStore 5200T
PowerStore 7000T
PowerStore 9000T
PowerStore 5000T
PowerStore 3200T
PowerStore 3200Q
PowerStore 1200T
PowerStore 3000T
PowerStore 9200T
ArubaOS-CX (AOS-CX)
LANTIME Operating System Firmware (LTOS)
PowerStoreT OS
Dell EMC VxRail Appliance
AirWave Management Platform
RSA Authentication Manager
Splunk Universal Forwarder
rsync (Ubuntu package)
rsync-debugsource
rsync-debuginfo
rsync
rsync-help
rsync (Debian package)
net-misc/rsync
rsync-daemon
rsync-doc
APEX Cloud Platform for Microsoft Azure
How to mitigate CVE-2024-12086
ArubaOS-CX (AOS-CX) - addressed in versions 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006
LANTIME Operating System Firmware (LTOS) - update to 7.08.021
Dell EMC VxRail Appliance - update to 8.321
RSA Authentication Manager - update to 8.7 SP2 Patch 6
Splunk Universal Forwarder - addressed in versions 9.3.12, 9.4.11, 10.0.6, 10.2.3
rsync (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.3-8ubuntu0.8, 3.1.3-8ubuntu0.9, 3.2.7-0ubuntu0.22.04.3, 3.2.7-0ubuntu0.22.04.4, 3.2.7-1ubuntu1.1, 3.2.7-1ubuntu1.2, 3.3.0-1ubuntu0.1, 3.3.0-1ubuntu0.2
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
rsync-debugsource - addressed in versions 3.1.3-3.18.1, 3.1.3-3.22.1, 3.2.3-150000.4.28.1, 3.2.3-150000.4.33.1, 3.2.3-150400.3.12.1, 3.2.3-150400.3.17.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1
rsync-debuginfo - addressed in versions 3.1.3-3.18.1, 3.1.3-3.22.1, 3.2.3-150000.4.28.1, 3.2.3-150000.4.33.1, 3.2.3-150400.3.12.1, 3.2.3-150400.3.17.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1
rsync - addressed in versions 3.1.3-3.18.1, 3.1.3-3.22.1, 3.2.3-150000.4.28.1, 3.2.3-150000.4.33.1, 3.2.3-150400.3.12.1, 3.2.3-150400.3.17.1, 3.2.7-150600.3.4.1, 3.2.7-150600.3.8.1
rsync-help - addressed in versions 3.1.3-11, 3.2.5-4, 3.2.7-6
rsync - addressed in versions 3.1.3-11, 3.2.5-4, 3.2.7-6
rsync-debuginfo - addressed in versions 3.1.3-11, 3.2.5-4, 3.2.7-6
rsync-debugsource - addressed in versions 3.1.3-11, 3.2.5-4, 3.2.7-6
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
rsync (Debian package) - update to 3.2.7-1+deb12u1
net-misc/rsync - update to 3.3.0-r2
rsync - update to 3.4.0
rsync - update to 3.4.0-1
rsync - addressed in versions 3.4.0-1.fc40, 3.4.0-1.fc41, 3.4.1-1.fc41
rsync - update to 3.4.1-1
rsync-daemon - update to 3.4.1-1
rsync-doc - update to 3.4.1-1
PowerStoreT OS - update to 4.0.1.3-2494147
Dell Secure Connect Gateway - update to 5.28.00.14
AirWave Management Platform - update to 8.3.0.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Rsync
- Arch Linux update for rsync
- Debian update for rsync
- Ubuntu update for rsync
- Fedora 40 update for rsync
- Fedora 41 update for rsync
- Slackware Linux update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- Gentoo update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- Fedora 41 update for rsync
- Ubuntu update for rsync
- openEuler 24.03 LTS update for rsync
- openEuler 20.03 LTS SP4 update for rsync
- openEuler 22.03 LTS SP3 update for rsync
- openEuler 24.03 LTS SP1 update for rsync
- openEuler 22.03 LTS SP4 update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- SUSE update for rsync
- Ubuntu update for rsync
- Ubuntu update for rsync
- Anolis OS update for rsync
- Dell VxRail Appliance 8.x update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- RSA Authentication Manager update for third-party components
- Meinberg LANTIME firmware update for third-party components (March 2025)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in Aruba Networking AOS-CX
- Multiple vulnerabilities in Aruba AirWave Management Platform
- Splunk Universal Forwarder update for third-party components (May 2026)