Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-12085

32
FAUCET Score

CVE-2024-12085 is a high-severity vulnerability in rsync that allows an attacker to leak one byte of uninitialized stack data at a time by manipulating checksum lengths during file comparisons. This flaw impacts numerous Linux distributions and products, including AlmaLinux, Arch Linux, Gentoo, NixOS, Red Hat, Samba, SUSE, and Triton DataCenter. With a CVSS score of 7.5 (High), the vulnerability is network-exploitable with low attack complexity, posing a significant risk of information disclosure. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion and media coverage, indicating a high level of awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.0CPE matchmatch criteria
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*
5.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift:5.0:*:*:*:*:*:*:*
4.12CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
4.13CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
4.14CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.65%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0866 is in the 91st percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (62)

microsoftpatch availablevia msrc
Product: 19944-17086Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.2.5-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 17120-16823Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 19946-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 17490-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.4.1-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: azl3 rsync 3.4.1-1 on Azure Linux 3.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: azl3 rsync 3.2.7-1 on Azure Linux 3.0Fixed in: 3.4.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: rsync-0:3.1.3-14.el8_6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: rsync-0:3.1.3-14.el8_6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: rsync-0:3.1.3-14.el8_6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: rsync-0:3.1.3-20.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rsync-0:3.2.3-20.el9_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: rsync-0:3.2.3-9.el9_0.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: rsync-0:3.2.3-19.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: rsync-0:3.2.3-19.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202502100314-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202503112237-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202502111902-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202501281917-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-ansible-rhel9-operator:v4.16.0-202501311735.p0.g2cb0020.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-helm-rhel9-operator:v4.16.0-202501311933.p0.g4246d04.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-operator-sdk-rhel9:v4.16.0-202501311605.p0.g4246d04.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202502051822-0
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/cluster-logging-operator-bundle:v5.8.17-22
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/cluster-logging-rhel9-operator:v5.8.17-10
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch6-rhel9:v6.8.1-454
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-operator-bundle:v5.8.17-17
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-537
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/elasticsearch-rhel9-operator:v5.8.17-4
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/eventrouter-rhel9:v0.4.0-339
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/fluentd-rhel9:v5.8.17-4
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-320
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-curator5-rhel9:v5.8.1-552
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-loki-rhel9:v3.3.2-9
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-view-plugin-rhel9:v5.8.17-5
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/loki-operator-bundle:v5.8.17-12
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/loki-rhel9-operator:v5.8.17-5
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/lokistack-gateway-rhel9:v0.1.0-725
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/opa-openshift-rhel9:v0.1.0-342
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/vector-rhel9:v0.28.1-88
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/cluster-logging-operator-bundle:v5.9.11-25
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/cluster-logging-rhel9-operator:v5.9.11-11
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/eventrouter-rhel9:v0.4.0-340
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/fluentd-rhel9:v5.9.11-5
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-321
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/logging-loki-rhel9:v3.3.2-8
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/loki-operator-bundle:v5.9.11-9
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/loki-rhel9-operator:v5.9.11-4
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/lokistack-gateway-rhel9:v0.1.0-724
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/opa-openshift-rhel9:v0.1.0-341
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/vector-rhel9:v0.34.1-30
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-must-gather-rhel8:sha256:b282ae2e5cfe451081785f221137d45d05320cf0017c3f1cba18a509d43eb6d9
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.9-RHEL-9Fixed in: openshift-logging/logging-view-plugin-rhel9:v5.9.11-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: rsync-0:3.0.6-12.el6_10.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: rsync-0:3.1.2-12.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: rsync-0:3.1.3-20.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: rsync-0:3.1.3-7.el8_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: rsync-0:3.1.3-12.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: rsync-0:3.1.3-12.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: rsync-0:3.1.3-12.el8_4.3
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rsync

Vendor Advisories (2)

redhatCVE-2024-12085Important

rsync: Info Leak via Uninitialized Stack Contents

Jan 14, 2025
microsoft2025-Jan/CVE-2024-12085Important

Rsync: info leak via uninitialized stack contents

Jan 14, 2025

References

github.com / google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2025/01/msg00008.html
security.netapp.com / advisory/ntap-20250131-0002
kb.cert.org / vuls/id/952657
access.redhat.com / errata/RHBA-2025:6470
access.redhat.com / errata/RHSA-2025:0324
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0325
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0637
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0688
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0714
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0774
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0787
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0790
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0849
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0884
Third Party Advisory
access.redhat.com / errata/RHSA-2025:0885
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1120
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1123
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1128
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1225
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1227
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1242
Third Party Advisory
access.redhat.com / errata/RHSA-2025:1451
Third Party Advisory
access.redhat.com / errata/RHSA-2025:21885
access.redhat.com / errata/RHSA-2025:2701
Third Party Advisory
access.redhat.com / security/cve/CVE-2024-12085
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
kb.cert.org / vuls/id/952657
Third Party Advisory