rsync-hns-650

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Share:

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server.

“The client requires only anonymous read-access to the server, such as public mirrors. Additionally, attackers can take control of a malicious server and read/write arbitrary files of any connected client. Sensitive data, such as SSH keys, can be extracted, and malicious code can be executed by overwriting files such as ~/.bashrc or ~/.popt,” CERT/CC noted.

About Rsync and the fixed vulnerabilities

Rsync is an open source utility used for synchronizing / transferring files and directories between different systems (computers, servers, storage devices, etc.), and is included by default in base installations of some Linux distributions.

“Rsync can also be used in Daemon mode and is widely used in in public mirrors to synchronize and distribute files efficiently across multiple servers,” CERT/CC added. “Many backup programs, such as Rclone, DeltaCopy, and ChronoSync use Rsync as backend software for file synchronization.”

The fixed vulnerabilities include:

  • CVE-2024-12084CVE-2024-12085 and CVE-2024-12086 are flaws in the Rsync daemon that could be exploited for remote code execution, leaking of stack data, and to read arbitrary files from the client’s machine (when they are being copied from a client to a server)
  • CVE-2024-12087 and CVE-2024-12088 affect the Rsync client and may allow a malicious server to write malicious files to arbitrary locations on connected clients
  • CVE-2024-12747 stems from Rsync improperly handling symbolic links during a race condition and can be used to leak sensitive information to the attacker

They all affect Rsync versions prior to v3.4.0, and CVE-2024-12084 is also present in v3.2.7 and higher. Mitigations for some the first two vulnerabilities are available (see here).

The first five flaws have been reported by Simon Scannell, Pedro Gallegos, and Jasiel Spelman at Google Cloud Vulnerability Research, and the last one by Aleksei Gorban.

What to do?

The Rsync maintainer has released a version with the fixes on Tuesday and users should implement them as soon as possible.

“As Rsync can be distributed bundled, ensure any software that provides such updates is also kept current to address these vulnerabilities,” CERT/CC says.

Updated Rsync packages have already been pushed out for Ubuntu and Debian.

CERT/CC’s list of affected OSes currently includes AlmaLinux OS, Arch Linux, Gentoo Linux, NixOS, Red Hat and SmartOS (i.e., the Triton DataCenter cloud management platform). The list will be updated as more information becomes available.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:58 pm, Jun 12, 2025
weather icon 22°C
L: 21° | H: 23°
clear sky
Humidity: 68 %
Pressure: 1014 mb
Wind: 8 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 23°°C 0 mm 0% 4 mph 68 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 27°°C 1 mm 100% 8 mph 91 % 1020 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
16° | 23°°C 1 mm 100% 15 mph 97 % 1019 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 23°°C 0 mm 0% 11 mph 87 % 1024 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 6 mph 82 % 1027 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 22°°C 0 mm 0% 4 mph 68 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 21°°C 0 mm 0% 4 mph 72 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 77 % 1019 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 6 mph 40 % 1020 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 7 mph 39 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 3 mph 54 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,244.50
-1.65%
Ethereum(ETH)
€2,327.98
-4.02%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.91
-3.43%
Solana(SOL)
€133.79
-4.69%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.159391
-5.28%
Shiba Inu(SHIB)
€0.000010
-5.97%
Pepe(PEPE)
€0.000010
-7.16%
Peanut the Squirrel(PNUT)
€0.236997
-5.02%
Scroll to Top