{"id":"UBUNTU-CVE-2024-52522","details":"Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.","modified":"2026-07-31T23:16:01.839497529Z","published":"2024-11-15T18:15:00Z","upstream":["CVE-2024-52522"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-52522"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-52522"},{"type":"REPORT","url":"https://github.com/rclone/rclone/security/advisories/GHSA-hrxh-9w67-g4cv"},{"type":"REPORT","url":"https://github.com/rclone/rclone/commit/01ccf204f42b4f68541b16843292439090a2dcf0"},{"type":"REPORT","url":"https://github.com/rclone/rclone/commit/669b2f2669cacd634faa2bcecb589b76e1402533"},{"type":"REPORT","url":"https://github.com/rclone/rclone/commit/01ccf204f42b4f68541b16843292439090a2dcf0"}],"affected":[{"package":{"name":"rclone","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/rclone?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.60.1+dfsg-2build1","1.60.1+dfsg-3","1.60.1+dfsg-3ubuntu0.24.04.1","1.60.1+dfsg-3ubuntu0.24.04.2","1.60.1+dfsg-3ubuntu0.24.04.3","1.60.1+dfsg-3ubuntu0.24.04.4","1.60.1+dfsg-3ubuntu0.24.04.4+esm1","1.60.1+dfsg-3ubuntu0.24.04.5","1.60.1+dfsg-3ubuntu0.24.04.5+esm1","1.60.1+dfsg-3ubuntu0.24.04.6","1.60.1+dfsg-3ubuntu0.24.04.6+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-rclone-rclone-dev","binary_version":"1.60.1+dfsg-3ubuntu0.24.04.6+esm1"},{"binary_version":"1.60.1+dfsg-3ubuntu0.24.04.6+esm1","binary_name":"rclone"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-52522.json"}},{"package":{"name":"rclone","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/rclone?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.60.1+dfsg-4","1.60.1+dfsg-4ubuntu1","1.60.1+dfsg-4ubuntu2","1.60.1+dfsg-4ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-rclone-rclone-dev","binary_version":"1.60.1+dfsg-4ubuntu2.1"},{"binary_name":"rclone","binary_version":"1.60.1+dfsg-4ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-52522.json"}},{"package":{"name":"rclone","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/rclone?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.60.1+dfsg-4ubuntu2","1.60.1+dfsg-4ubuntu3","1.60.1+dfsg-4ubuntu3.1","1.60.1+dfsg-4ubuntu3.1+esm1","1.60.1+dfsg-4ubuntu3.2","1.60.1+dfsg-4ubuntu3.2+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-rclone-rclone-dev","binary_version":"1.60.1+dfsg-4ubuntu3.2+esm1"},{"binary_name":"rclone","binary_version":"1.60.1+dfsg-4ubuntu3.2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-52522.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"},{"type":"Ubuntu","score":"medium"}]}