CVE-2024-12084
CRITICALSamba Rsync < 24.11 - Out-of-Bounds Write
Title source: ruleDescription
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
Exploits (3)
References (8)
Scores
CVSS v3
9.8
EPSS
0.0346
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-122
CWE-787
Status
published
Products (10)
almalinux/almalinux
10.0
archlinux/arch_linux
gentoo/linux
nixos/nixos
24.11
nixos/nixos
< 24.11
novell/suse_linux
redhat/enterprise_linux
10.0
samba/rsync
3.2.7
samba/rsync
3.3.0
tritondatacenter/smartos
< 20250123
Published
Jan 15, 2025
Tracked Since
Feb 18, 2026