← Back to browse · API

CVE-2024-12084

Severity
CRITICAL
CVSS
9.8
EPSS
0.72059
Risk score
64.42
CISA KEV
No
PoC
No
Published
2025-01-15
Modified
2026-06-29
First seen
2026-08-07
Aliases
EUVD-2024-50580, GHSA-85H7-M8C3-V9WC
Products
Red Hat:Red Hat Enterprise Linux 10 patch: 0:3.4.1-2.el10
Sources
euvd EUVD-2024-50580

Description

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

References