Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 72.1%top 0.61%Exploited in the wild

Rsync: Mehrere Schwachstellen

0
Critical
Published: 08/12/2026 (08/12/2026, 22:00:00 UTC)
Source: GCVE Database
Vendor/Project: Bundesamt für Sicherheit in der Informationstechnik
Product: Fedora

Observed in the wild — via OffSeq Mirage

1,056
honeypot exploit hits
97
attacker networks (/16)
First seen 06/24/2026 · last seen 07/02/2026 · activity in US, BR, BE, NL, FR, JP, SG, GB
View live telemetry on OffSeq Mirage

Description

Rsync ist ein Tool, um Dateien und Verzeichnisse zu synchronisieren.

Affected software

Affected versions
>=10.0 <10.3Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)srcFedoraFedora LinuxOpen SourceRsync<3.5.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 20:16:21 UTC

Technical Analysis

Red Hat Product Security has released a bug fix advisory (RHBA-2025:6470) addressing multiple critical vulnerabilities in the rsync utility packaged with Red Hat Enterprise Linux 10. The advisory covers six CVEs (CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747) involving issues such as heap-based buffer overflows (CWE-122), race conditions (CWE-362), improper input validation (CWE-22), and other memory safety concerns (CWE-908, CWE-390). The update includes building rsync with the --with-rrsync option and upgrading to rsync version 3.4.1-2.el10. The advisory applies to Red Hat Enterprise Linux 10 across multiple architectures including x86_64, s390x, ppc64le, and aarch64. Known exploits targeting these vulnerabilities have been reported in the wild. Red Hat provides official patches and detailed update instructions in their errata and release notes.

Potential Impact

The vulnerabilities fixed in this advisory are critical and have known exploits in the wild, indicating active exploitation. They could allow attackers to cause memory corruption, race conditions, or path traversal attacks via the rsync utility, potentially leading to denial of service or unauthorized access. The presence of multiple CWE categories related to memory safety and race conditions underscores the severity of the risk. Systems running affected versions of Red Hat Enterprise Linux 10 with vulnerable rsync packages are at risk until updated.

Mitigation Recommendations

Red Hat has released an official patch update for rsync in Red Hat Enterprise Linux 10 (rsync-3.4.1-2.el10) that addresses these vulnerabilities. Users should apply this update promptly following Red Hat's published instructions at https://access.redhat.com/articles/11258. The advisory indicates that the fix is available and remediation is official. No additional mitigation steps beyond applying the update are specified by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHBA-2025:6470
Cve Count
6
Additional Cves
["CVE-2024-12085","CVE-2024-12086","CVE-2024-12087","CVE-2024-12088","CVE-2024-12747"]
Cvss Version
3.1

Threat ID: 6a160988e29bf47b50652ec9

Added to database: 05/26/2026, 20:58:48 UTC

Last enriched: 08/11/2026, 20:16:21 UTC

Last updated: 08/31/2026, 15:42:05 UTC

Views: 139

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses