{"id":"CVE-2024-12084","summary":"Rsync: heap buffer overflow in rsync due to improper checksum length handling","details":"A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.","aliases":["CVE-2024-12085","CVE-2024-12086","CVE-2024-12087","CVE-2024-12088","GHSA-p5pg-x43v-mvqj"],"modified":"2026-08-27T03:30:58.441131869Z","published":"2025-01-15T14:16:35.363Z","related":["SUSE-SU-2025:0156-1","SUSE-SU-2025:20122-1","SUSE-SU-2025:20223-1","SUSE-SU-2026:2038-1","SUSE-SU-2026:2048-1","SUSE-SU-2026:2083-1","SUSE-SU-2026:21726-1","USN-7206-3","openSUSE-SU-2025:14665-1"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12084.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/01/14/6"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/952657"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/952657"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2025:6470"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-12084"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12084.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12084"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250131-0002/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2330527"},{"type":"PACKAGE","url":"https://github.com/RsyncProject/rsync"},{"type":"EVIDENCE","url":"https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.samba.org/rsync.git/","events":[{"introduced":"6b5ae825db985e9d1c98576651b50c8e490ddb97"},{"last_affected":"6c8ca91c731b7bf2b081694bda85b7dadc2b7aff"}],"database_specific":{"extracted_events":[{"introduced":"3.2.7-NA"},{"last_affected":"3.2.7-NA"},{"introduced":"3.3.0-NA"},{"last_affected":"3.3.0-NA"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:samba:rsync:3.2.7:-:*:*:*:*:*:*","cpe:2.3:a:samba:rsync:3.3.0:-:*:*:*:*:*:*"]}},{"type":"GIT","repo":"https://github.com/rsyncproject/rsync","events":[{"introduced":"6b5ae825db985e9d1c98576651b50c8e490ddb97"},{"last_affected":"6c8ca91c731b7bf2b081694bda85b7dadc2b7aff"}],"database_specific":{"extracted_events":[{"introduced":"3.2.7"},{"last_affected":"3.2.7"},{"introduced":"3.3.0"},{"last_affected":"3.3.0"},{"introduced":"3.2.7-NA"},{"last_affected":"3.2.7-NA"},{"introduced":"3.3.0-NA"},{"last_affected":"3.3.0-NA"}],"source":["AFFECTED_FIELD","CPE_STRING"],"cpe":["cpe:2.3:a:samba:rsync:3.2.7:-:*:*:*:*:*:*","cpe:2.3:a:samba:rsync:3.3.0:-:*:*:*:*:*:*"]}}],"versions":["3.2.7","3.2.7-NA","3.3.0","3.3.0-NA","v3.2.7","v3.3.0","v3.3.0pre1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12084.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}