Rsync: Mehrere Schwachstellen
Rsync ist ein Tool, um Dateien und Verzeichnisse zu synchronisieren.
AI Analysis
Technical Summary
Red Hat Product Security has released a bug fix advisory (RHBA-2025:6470) addressing multiple critical vulnerabilities in the rsync utility packaged with Red Hat Enterprise Linux 10. The advisory covers six CVEs (CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747) involving issues such as heap-based buffer overflows (CWE-122), race conditions (CWE-362), improper input validation (CWE-22), and other memory safety concerns (CWE-908, CWE-390). The update includes building rsync with the --with-rrsync option and upgrading to rsync version 3.4.1-2.el10. The advisory applies to Red Hat Enterprise Linux 10 across multiple architectures including x86_64, s390x, ppc64le, and aarch64. Known exploits targeting these vulnerabilities have been reported in the wild. Red Hat provides official patches and detailed update instructions in their errata and release notes.
Potential Impact
The vulnerabilities fixed in this advisory are critical and have known exploits in the wild, indicating active exploitation. They could allow attackers to cause memory corruption, race conditions, or path traversal attacks via the rsync utility, potentially leading to denial of service or unauthorized access. The presence of multiple CWE categories related to memory safety and race conditions underscores the severity of the risk. Systems running affected versions of Red Hat Enterprise Linux 10 with vulnerable rsync packages are at risk until updated.
Mitigation Recommendations
Red Hat has released an official patch update for rsync in Red Hat Enterprise Linux 10 (rsync-3.4.1-2.el10) that addresses these vulnerabilities. Users should apply this update promptly following Red Hat's published instructions at https://access.redhat.com/articles/11258. The advisory indicates that the fix is available and remediation is official. No additional mitigation steps beyond applying the update are specified by the vendor.
Rsync: Mehrere Schwachstellen
Observed in the wild — via OffSeq Mirage
Description
Rsync ist ein Tool, um Dateien und Verzeichnisse zu synchronisieren.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Product Security has released a bug fix advisory (RHBA-2025:6470) addressing multiple critical vulnerabilities in the rsync utility packaged with Red Hat Enterprise Linux 10. The advisory covers six CVEs (CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747) involving issues such as heap-based buffer overflows (CWE-122), race conditions (CWE-362), improper input validation (CWE-22), and other memory safety concerns (CWE-908, CWE-390). The update includes building rsync with the --with-rrsync option and upgrading to rsync version 3.4.1-2.el10. The advisory applies to Red Hat Enterprise Linux 10 across multiple architectures including x86_64, s390x, ppc64le, and aarch64. Known exploits targeting these vulnerabilities have been reported in the wild. Red Hat provides official patches and detailed update instructions in their errata and release notes.
Potential Impact
The vulnerabilities fixed in this advisory are critical and have known exploits in the wild, indicating active exploitation. They could allow attackers to cause memory corruption, race conditions, or path traversal attacks via the rsync utility, potentially leading to denial of service or unauthorized access. The presence of multiple CWE categories related to memory safety and race conditions underscores the severity of the risk. Systems running affected versions of Red Hat Enterprise Linux 10 with vulnerable rsync packages are at risk until updated.
Mitigation Recommendations
Red Hat has released an official patch update for rsync in Red Hat Enterprise Linux 10 (rsync-3.4.1-2.el10) that addresses these vulnerabilities. Users should apply this update promptly following Red Hat's published instructions at https://access.redhat.com/articles/11258. The advisory indicates that the fix is available and remediation is official. No additional mitigation steps beyond applying the update are specified by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHBA-2025:6470
- Cve Count
- 6
- Additional Cves
- ["CVE-2024-12085","CVE-2024-12086","CVE-2024-12087","CVE-2024-12088","CVE-2024-12747"]
- Cvss Version
- 3.1
Threat ID: 6a160988e29bf47b50652ec9
Added to database: 05/26/2026, 20:58:48 UTC
Last enriched: 08/11/2026, 20:16:21 UTC
Last updated: 08/31/2026, 15:42:05 UTC
Views: 139
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.