rsync-hns-650

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Share:

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server.

“The client requires only anonymous read-access to the server, such as public mirrors. Additionally, attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted, and malicious code can be executed by overwriting files such as ~/.bashrc or ~/.popt,” CERT/CC noted.

About Rsync and the fixed vulnerabilities

Rsync is an open source utility used for synchronizing / transferring files and directories between different systems (computers, servers, storage devices, etc.), and is included by default in base installations of some Linux distributions.

“Rsync can also be used in Daemon mode and is widely used in in public mirrors to synchronize and distribute files efficiently across multiple servers,” CERT/CC added. “Many backup programs, such as Rclone, DeltaCopy, and ChronoSync use Rsync as backend software for file synchronization.”

The fixed vulnerabilities include:

  • CVE-2024-12084CVE-2024-12085 and CVE-2024-12086 are flaws in the Rsync daemon that could be exploited for remote code execution, leaking of stack data, and to read arbitrary files from the client’s machine (when they are being copied from a client to a server)
  • CVE-2024-12087 and CVE-2024-12088 affect the Rsync client and may allow a malicious server to write malicious files to arbitrary locations on connected clients
  • CVE-2024-12747 stems from Rsync improperly handling symbolic links during a race condition and can be used to leak sensitive information to the attacker

They all affect Rsync versions prior to v3.4.0, and CVE-2024-12084 is also present in v3.2.7 and higher. Mitigations for some the first two vulnerabilities are available (see here).

The first five flaws have been reported by Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research, and the last one by Aleksei Gorban.

What to do?

The Rsync maintainer has released a version with the fixes on Tuesday and users should implement them as soon as possible.

“As Rsync can be distributed bundled, ensure any software that provides such updates is also kept current to address these vulnerabilities,” CERT/CC says.

Updated Rsync packages have already been pushed out for Ubuntu and Debian.

CERT/CC’s list of affected OSes currently includes AlmaLinux OS, Arch Linux, Gentoo Linux, NixOS, Red Hat and SmartOS (i.e., the Triton DataCenter cloud management platform). The list will be updated as more information becomes available.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:44 am, Apr 28, 2025
weather icon 20°C
L: 19° | H: 22°
scattered clouds
Humidity: 52 %
Pressure: 1027 mb
Wind: 2 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 43%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:37 am
Sunset: 8:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 8 mph 58 % 1027 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 10 mph 67 % 1027 mb 0 mm/h
Wed Apr 30 10:00 pm
weather icon
11° | 23°°C 0 mm 0% 8 mph 77 % 1025 mb 0 mm/h
Thu May 01 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 9 mph 79 % 1020 mb 0 mm/h
Fri May 02 10:00 pm
weather icon
14° | 22°°C 0 mm 0% 8 mph 91 % 1022 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 21°°C 0 mm 0% 3 mph 52 % 1027 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 48 % 1026 mb 0 mm/h
Today 7:00 pm
weather icon
16° | 18°°C 0 mm 0% 8 mph 50 % 1026 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 4 mph 58 % 1027 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 4 mph 56 % 1027 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 4 mph 63 % 1027 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 4 mph 67 % 1027 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 54 % 1027 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€83,752.78
1.09%
Ethereum(ETH)
€1,595.38
0.07%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€2.05
7.00%
Solana(SOL)
€134.39
2.87%
USDC(USDC)
€0.88
0.01%
Dogecoin(DOGE)
€0.159697
0.04%
Shiba Inu(SHIB)
€0.000012
3.19%
Pepe(PEPE)
€0.000008
1.26%
Scroll to Top