Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-12084

75
FAUCET Score

CVE-2024-12084 is a critical heap-based buffer overflow vulnerability in the rsync daemon, affecting numerous Linux distributions and products including AlmaLinux, Arch Linux, Gentoo, NixOS, Novell, Red Hat, Samba, and TritonDataCenter. This flaw stems from improper handling of attacker-controlled checksum lengths, allowing out-of-bounds writes. With a CVSS score of 9.8, it presents a critical risk, enabling unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
3.2.7CPE matchmatch criteria
cpe:2.3:a:samba:rsync:3.2.7:-:*:*:*:*:*:*
3.3.0CPE matchmatch criteria
cpe:2.3:a:samba:rsync:3.3.0:-:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:almalinux:almalinux:10.0:-:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:archlinux:arch_linux:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:gentoo:linux:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
72.06%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.7206 is in the 98th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: azl3 rsync 3.2.7-1 on Azure Linux 3.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: azl3 rsync 3.4.1-1 on Azure Linux 3.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.2.5-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 17120-16823Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 17490-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 19944-17086Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 19946-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.4.1-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rsync-0:3.4.1-2.el10
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

redhatCVE-2024-12084Critical

rsync: Heap Buffer Overflow in Rsync due to Improper Checksum Length Handling

Jan 14, 2025
microsoft2025-Jan/CVE-2024-12084Critical

Rsync: heap buffer overflow in rsync due to improper checksum length handling

Jan 14, 2025

References

github.com / google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
ExploitVendor Advisory
security.netapp.com / advisory/ntap-20250131-0002
kb.cert.org / vuls/id/952657
openwall.com / lists/oss-security/2025/01/14/6
Mailing ListThird Party Advisory
access.redhat.com / errata/RHBA-2025:6470
access.redhat.com / security/cve/CVE-2024-12084
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
kb.cert.org / vuls/id/952657
Third Party Advisory