CVE-2024-12084

CRITICAL

Samba Rsync < 24.11 - Out-of-Bounds Write

Title source: rule

Description

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

Exploits (3)

nomisec SCANNER 4 stars
by themirze · poc
https://github.com/themirze/cve-2024-12084
nomisec WORKING POC 1 stars
by InkeyP · poc
https://github.com/InkeyP/CVE-2024-12084
nomisec SCANNER
by rxerium · poc
https://github.com/rxerium/CVE-2024-12084

Scores

CVSS v3 9.8
EPSS 0.0346
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-122 CWE-787
Status published
Products (10)
almalinux/almalinux 10.0
archlinux/arch_linux
gentoo/linux
nixos/nixos 24.11
nixos/nixos < 24.11
novell/suse_linux
redhat/enterprise_linux 10.0
samba/rsync 3.2.7
samba/rsync 3.3.0
tritondatacenter/smartos < 20250123
Published Jan 15, 2025
Tracked Since Feb 18, 2026