CVE-2024-12085
Executive Summary
A flaw in rsync’s checksum comparison allows an attacker to set the s2length parameter to trigger a comparison between a valid checksum and uninitialized stack memory. Each comparison leaks one byte of uninitialized data, enabling a gradual information‑disclosure attack. The vulnerability is not yet listed in CISA KEV but could expose sensitive data if exploited.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2025-01-14T18:15:25.123 - Last Modified: 2026-08-23T02:16:54.680
Original Description: A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
"Self-complacency is fatal to progress."
— Margaret Sangster