Arch Linux is a lightweight, rolling-release Linux distribution maintained by a small community and widely used by advanced users and embedded systems where minimal footprint and rapid package updates are valued. Its vulnerabilities cluster in the core operating system and package-management components and skew toward serious outcomes, reflecting both the direct kernel and userspace exposure and the architectural demands of a rolling-distribution model where fixes must propagate rapidly across a large installed base. The recurring weakness classes—including path traversal, buffer overflows, improper privilege management, and error-handling gaps—are characteristic of systems-level software where memory safety and access control directly impact system integrity. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Archlinux over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
CVE-2024-12085HIGH A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis | Jan 14, 2025 | 7.5 | 32 | NO | NO |
CVE-2024-12088HIGH A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symb | Jan 14, 2025 | 7.5 | 28 | NO | NO |
CVE-2024-12087HIGH A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled | Jan 14, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-12086MEDIUM A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a cl | Jan 14, 2025 | 6.8 | 25 | NO | NO |
CVE-2020-5291HIGH Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the | Mar 31, 2020 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Archlinux.
Media articles that mention a CVE ID that affects a product developed by Archlinux — matched by CVE ID, not by vendor name.