High [CVE-2024-12085] info leak via uninitialized stack contents
This high-severity Red Hat Linux advisory covers CVE-2024-12085 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
This vulnerability is rated as having Important impact as it helps bypass Address Space Layout Randomization (ASLR). ASLR is a memory protection system which makes the exploitation of memory corruption vulnerabilities more difficult.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-908.
Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 21 more.
Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Telecommunications Update Service; Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 17 more.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
- rsync-0:3.4.1-2.el10
- rsync-0:3.0.6-12.el6_10.1
- rsync-0:3.1.2-12.el7_9.1
- rsync-0:3.1.3-20.el8_10
- rsync-0:3.1.3-7.el8_2.3
- rsync-0:3.1.3-12.el8_4.3
- rsync-0:3.1.3-14.el8_6.6
- rsync-0:3.1.3-20.el8_8.1
- rsync-0:3.2.3-20.el9_5.1
- rsync-0:3.2.3-9.el9_0.3
- rsync-0:3.2.3-19.el9_2.1
- rsync-0:3.2.3-19.el9_4.1
- rhcos-412.86.202502100314-0
- rhcos-413.92.202503112237-0
- rhcos-414.92.202502111902-0
- rhcos-415.92.202501281917-0
- openshift4/ose-ansible-rhel9-operator:v4.16.0-202501311735.p0.g2cb0020.assembly.stream.el9
- openshift4/ose-helm-rhel9-operator:v4.16.0-202501311933.p0.g4246d04.assembly.stream.el9
- openshift4/ose-operator-sdk-rhel9:v4.16.0-202501311605.p0.g4246d04.assembly.stream.el9
- rhcos-417.94.202502051822-0
- openshift4/aws-kms-encryption-provider-rhel9:v4.18.0-202501230001.p0.g088dcaf.assembly.stream.el9
- openshift4/azure-kms-encryption-provider-rhel9:v4.18.0-202501230001.p0.gd4fb1b6.assembly.stream.el9
- openshift4/azure-service-rhel9-operator:v4.18.0-202501230001.p0.g11ced00.assembly.stream.el9
- openshift4/cloud-network-config-controller-rhel9:v4.18.0-202501230001.p0.gf648c78.assembly.stream.el9
- openshift4/container-networking-plugins-microshift-rhel9:v4.18.0-202501230001.p0.g24a6532.assembly.stream.el9
- openshift4/driver-toolkit-rhel9:v4.18.0-202502100301.p0.g2e139ed.assembly.stream.el9
- openshift4/egress-router-cni-rhel9:v4.18.0-202501230001.p0.g3193a75.assembly.stream.el9
- openshift4/frr-rhel9:v4.18.0-202502041302.p0.g1ad8f2e.assembly.stream.el9
- openshift4/insights-runtime-exporter-rhel9:v4.18.0-202501230001.p0.g7149f2d.assembly.stream.el9
- openshift4/insights-runtime-extractor-rhel9:v4.18.0-202501230001.p0.g7149f2d.assembly.stream.el9
- openshift4/kube-metrics-server-rhel9:v4.18.0-202501230001.p0.g962ccca.assembly.stream.el9
- openshift4/kubevirt-csi-driver-rhel9:v4.18.0-202501230001.p0.gba2234b.assembly.stream.el9
- openshift4/network-tools-rhel9:v4.18.0-202502111035.p0.gf76635f.assembly.stream.el9
- openshift4/oc-mirror-plugin-rhel9:v4.18.0-202502100934.p0.gc00c7c9.assembly.stream.el9
- openshift4/openshift-route-controller-manager-rhel9:v4.18.0-202501230001.p0.g07daee4.assembly.stream.el9
- openshift4/ose-agent-installer-api-server-rhel9:v4.18.0-202502040032.p0.ge5a4005.assembly.stream.el9
- openshift4/ose-agent-installer-csr-approver-rhel9:v4.18.0-202502040032.p0.g5348c85.assembly.stream.el9
- openshift4/ose-agent-installer-node-agent-rhel9:v4.18.0-202502041302.p0.g51a74ac.assembly.stream.el9
- openshift4/ose-agent-installer-orchestrator-rhel9:v4.18.0-202501230001.p0.g5348c85.assembly.stream.el9
- openshift4/ose-agent-installer-utils-rhel9:v4.18.0-202501230001.p0.g3f6d1d8.assembly.stream.el9
- RHBA-2025:6470
- RHSA-2025:0849
- RHSA-2025:0714
- RHSA-2025:0325
- RHSA-2025:0884
- RHSA-2025:0885
- RHSA-2025:0790
- RHSA-2025:0787
- RHSA-2025:0324
- RHSA-2025:0688
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
Mitigation checklist
- Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure.
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.