Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2024-12085

CVE-2024-12085: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2024-12085] info leak via uninitialized stack contents

    CVE-2024-12085Source published Source updated

    A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. This vulnerability is rated as having Important impact as it helps bypass Address Space Layout Randomization (ASLR). ASLR is a memory protection system which makes the exploitation of memory corruption vulnerabilities more difficult. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
    • Red Hat Enterprise Linux 7 Extended Lifecycle Support
    • Red Hat Enterprise Linux 8.2 Advanced Update Support

    21 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • rsync-0:3.4.1-2.el10
    • rsync-0:3.0.6-12.el6_10.1
    • rsync-0:3.1.2-12.el7_9.1
    • rsync-0:3.1.3-20.el8_10

    46 more entries in the full advisory.

    Mitigation guidance
    • Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery