← Vulnerability feed

Vulnerability record · CVE-2024-12084 · published 15 January 2025

CVE-2024-12084: rsync daemon heap buffer overflow via attacker-controlled checksum length

Samba · Rsync

The rsync daemon mishandles attacker-controlled checksum lengths (s2length), allowing an out-of-bounds write in the sum2 buffer when MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH of 16 bytes. This is a remotely reachable heap-based buffer overflow in a widely deployed file synchronization service.

9.8 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
8References, 1 tagged exploit
29 Jun 2026Last modified by NVD

Description

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and very high EPSS plus public exploit references make this a top remediation priority.

What it is

The rsync daemon mishandles attacker-controlled checksum lengths (s2length), allowing an out-of-bounds write in the sum2 buffer when MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH of 16 bytes. This is a remotely reachable heap-based buffer overflow in a widely deployed file synchronization service.

Impact

An unauthenticated remote attacker can write out of bounds on the heap, which can corrupt memory and potentially lead to code execution or daemon crash.

Attack surface

Reached over the network against an exposed rsync daemon; the CVSS vector shows no privileges or user interaction required. Any host running a vulnerable rsync daemon with network exposure is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is 0.72059 (99.4th percentile), indicating high predicted exploitation activity. A reference is tagged Exploit, so public exploit material exists.

What to do

  • Patch rsync to a fixed version per vendor advisories (Red Hat, Samba, CERT/CC) as the first action.
  • Restrict network access to rsync daemons to trusted hosts and disable anonymous or unauthenticated rsync modules.
  • Run rsync daemons with least privilege and consider sandboxing or container isolation to limit heap corruption impact.
  • Monitor vendor errata and CERT/CC advisory VU#952657 for updated fixed versions and guidance.

Detection

  • Inspect rsync daemon logs for malformed or anomalous checksum negotiation and unexpected connection patterns.
  • Monitor for rsync daemon crashes or abnormal process termination that could indicate heap corruption attempts.
  • Use network monitoring to flag rsync traffic from untrusted sources to exposed daemons.
  • Check host memory integrity tooling or EDR for out-of-bounds write indicators in rsync processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-12084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed10.0CVE-2010-3912Novell suse linux vulnerabilityThe supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has u…EPSS 2.1%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0990Gd graphics library gdlib vulnerabilityInteger overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and …EPSS 28%10.0CVE-2004-1034Kaffeine player vulnerabilityBuffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a d…EPSS 5.7%10.0CVE-2004-1037TWiki search function allows remote command executionThe search function in TWiki 20030201 passes user-supplied search strings to a shell without sanitizing shell metacharacters, allowing command inject…EPSS 62%analysed10.0CVE-2004-1052Bnc vulnerabilityBuffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an…EPSS 3.6%10.0CVE-2004-0947Arj software inc. unarj vulnerabilityBuffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.EPSS 7.4%

Source: NIST National Vulnerability Database (record CVE-2024-12084), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.