Critical severity9.8NVD Advisory· Published Jan 15, 2025· Updated Jun 29, 2026
CVE-2024-12084
CVE-2024-12084
Description
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords6 versionspkg:deb/ubuntu/rsync@3.3.0-1ubuntu0.1?arch=source&distro=oracularpkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/rsync&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rsync&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/rsync&distro=SUSE%20Linux%20Micro%206.1
< 3.3.0-1ubuntu0.1+ 5 more
- (no CPE)range: < 3.3.0-1ubuntu0.1
- (no CPE)range: < 3.2.7-150600.3.8.1
- (no CPE)range: < 3.4.1-1.1
- (no CPE)range: < 3.2.7-150600.3.8.1
- (no CPE)range: < 3.2.7-4.1
- (no CPE)range: < 3.3.0-slfo.1.1_3.1
Patches
Vulnerability mechanics
References
8- github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqjnvdExploitVendor Advisory
- www.openwall.com/lists/oss-security/2025/01/14/6nvdMailing ListThird Party Advisory
- access.redhat.com/security/cve/CVE-2024-12084nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- kb.cert.org/vuls/id/952657nvdThird Party Advisory
- access.redhat.com/errata/RHBA-2025:6470nvd
- security.netapp.com/advisory/ntap-20250131-0002/nvd
- www.kb.cert.org/vuls/id/952657nvd
News mentions
1- GitLab Patch Release: 18.1.2, 18.0.4, 17.11.6GitLab Security Releases · Jul 9, 2025