AlmaLinux is a community-driven Linux distribution that, despite a narrow product focus, serves as a drop-in replacement for enterprise systems across a wide range of deployments. Vulnerabilities affecting the distribution skew toward serious outcomes and frequently acquire public exploit code, reflecting the kernel and system-library exposure inherent to a full operating system. The durable signal centers on low-level weakness classes including path traversal, race conditions, buffer overflows, and out-of-bounds writes that recur across the underlying packages and kernel components the distribution integrates. Current severity, exploitation activity, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Almalinux over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
CVE-2024-12085HIGH A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis | Jan 14, 2025 | 7.5 | 32 | NO | NO |
CVE-2024-12088HIGH A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symb | Jan 14, 2025 | 7.5 | 28 | NO | NO |
CVE-2024-12087HIGH A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled | Jan 14, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-12086MEDIUM A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a cl | Jan 14, 2025 | 6.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Almalinux.
Media articles that mention a CVE ID that affects a product developed by Almalinux — matched by CVE ID, not by vendor name.