Vulnerability record · CVE-2024-12084 · published 15 January 2025
CVE-2024-12084: rsync daemon heap buffer overflow via attacker-controlled checksum length
Samba · Rsync
The rsync daemon mishandles attacker-controlled checksum lengths (s2length), allowing an out-of-bounds write in the sum2 buffer when MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH of 16 bytes. This is a remotely reachable heap-based buffer overflow in a widely deployed file synchronization service.
Description
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and very high EPSS plus public exploit references make this a top remediation priority.
What it is
The rsync daemon mishandles attacker-controlled checksum lengths (s2length), allowing an out-of-bounds write in the sum2 buffer when MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH of 16 bytes. This is a remotely reachable heap-based buffer overflow in a widely deployed file synchronization service.
Impact
An unauthenticated remote attacker can write out of bounds on the heap, which can corrupt memory and potentially lead to code execution or daemon crash.
Attack surface
Reached over the network against an exposed rsync daemon; the CVSS vector shows no privileges or user interaction required. Any host running a vulnerable rsync daemon with network exposure is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is 0.72059 (99.4th percentile), indicating high predicted exploitation activity. A reference is tagged Exploit, so public exploit material exists.
What to do
- Patch rsync to a fixed version per vendor advisories (Red Hat, Samba, CERT/CC) as the first action.
- Restrict network access to rsync daemons to trusted hosts and disable anonymous or unauthenticated rsync modules.
- Run rsync daemons with least privilege and consider sandboxing or container isolation to limit heap corruption impact.
- Monitor vendor errata and CERT/CC advisory VU#952657 for updated fixed versions and guidance.
Detection
- Inspect rsync daemon logs for malformed or anomalous checksum negotiation and unexpected connection patterns.
- Monitor for rsync daemon crashes or abnormal process termination that could indicate heap corruption attempts.
- Use network monitoring to flag rsync traffic from untrusted sources to exposed daemons.
- Check host memory integrity tooling or EDR for out-of-bounds write indicators in rsync processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHBA-2025:6470 | |
| https://access.redhat.com/security/cve/CVE-2024-12084 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2330527 | Issue TrackingThird Party Advisory |
| https://kb.cert.org/vuls/id/952657 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/01/14/6 | Mailing ListThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20250131-0002/ | |
| https://www.kb.cert.org/vuls/id/952657 | |
| https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj | ExploitVendor Advisory |
Track CVE-2024-12084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-12084), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.