rsync-hns-650

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Share:

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server.

“The client requires only anonymous read-access to the server, such as public mirrors. Additionally, attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted, and malicious code can be executed by overwriting files such as ~/.bashrc or ~/.popt,” CERT/CC noted.

About Rsync and the fixed vulnerabilities

Rsync is an open source utility used for synchronizing / transferring files and directories between different systems (computers, servers, storage devices, etc.), and is included by default in base installations of some Linux distributions.

“Rsync can also be used in Daemon mode and is widely used in in public mirrors to synchronize and distribute files efficiently across multiple servers,” CERT/CC added. “Many backup programs, such as Rclone, DeltaCopy, and ChronoSync use Rsync as backend software for file synchronization.”

The fixed vulnerabilities include:

  • CVE-2024-12084CVE-2024-12085 and CVE-2024-12086 are flaws in the Rsync daemon that could be exploited for remote code execution, leaking of stack data, and to read arbitrary files from the client’s machine (when they are being copied from a client to a server)
  • CVE-2024-12087 and CVE-2024-12088 affect the Rsync client and may allow a malicious server to write malicious files to arbitrary locations on connected clients
  • CVE-2024-12747 stems from Rsync improperly handling symbolic links during a race condition and can be used to leak sensitive information to the attacker

They all affect Rsync versions prior to v3.4.0, and CVE-2024-12084 is also present in v3.2.7 and higher. Mitigations for some the first two vulnerabilities are available (see here).

The first five flaws have been reported by Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research, and the last one by Aleksei Gorban.

What to do?

The Rsync maintainer has released a version with the fixes on Tuesday and users should implement them as soon as possible.

“As Rsync can be distributed bundled, ensure any software that provides such updates is also kept current to address these vulnerabilities,” CERT/CC says.

Updated Rsync packages have already been pushed out for Ubuntu and Debian.

CERT/CC’s list of affected OSes currently includes AlmaLinux OS, Arch Linux, Gentoo Linux, NixOS, Red Hat and SmartOS (i.e., the Triton DataCenter cloud management platform). The list will be updated as more information becomes available.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:53 am, Jul 1, 2025
weather icon 30°C
L: 28° | H: 31°
overcast clouds
Humidity: 52 %
Pressure: 1013 mb
Wind: 3 mph SSW
Wind Gust: 4 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 97%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:47 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
28° | 31°°C 0 mm 0% 10 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 22°°C 1 mm 100% 10 mph 88 % 1023 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
13° | 26°°C 0 mm 0% 9 mph 56 % 1029 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 9 mph 50 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 23°°C 1 mm 100% 14 mph 93 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 7 mph 47 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 33°°C 0 mm 0% 10 mph 33 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
31° | 31°°C 0 mm 0% 10 mph 33 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 61 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 6 mph 70 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 4 mph 62 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,387.17
-0.96%
Ethereum(ETH)
€2,081.90
-0.41%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
0.89%
Solana(SOL)
€126.21
-0.84%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.136607
-2.61%
Shiba Inu(SHIB)
€0.000009
-2.08%
Pepe(PEPE)
€0.000008
-3.39%
Scroll to Top