A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checks…
High CVSS 7.5
Summary
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
- :
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHBA-2025:6470
- https://access.redhat.com/errata/RHSA-2025:0324 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0325 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0637 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0688 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0714 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0774 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0787 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0790 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0849 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0884 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:0885 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1120 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1123 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1128 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1225 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1227 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1242 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:1451 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:21885
- https://access.redhat.com/errata/RHSA-2025:2701 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-12085 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2330539 Issue Tracking
- https://kb.cert.org/vuls/id/952657 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html
- https://security.netapp.com/advisory/ntap-20250131-0002/
- https://www.kb.cert.org/vuls/id/952657
- https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj Exploit
Timeline
- nvd_ingest NVD