CVE-2024-12084: Almalinux

Critical severity, CVSS 9.8. EPSS: 72.1% chance of exploitation in the next 30 days.

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

Affected products

  • Almalinux Almalinux: version 10.0 only
  • Archlinux Arch Linux: affected versions not specified
  • Gentoo Linux: affected versions not specified
  • Nixos Nixos: before 24.11 (fixed in 24.11); version 24.11 only
  • Novell Suse Linux: affected versions not specified
  • Red Hat Enterprise Linux: version 10.0 only
  • Samba Rsync: version 3.2.7 only; version 3.3.0 only
  • Tritondatacenter Smartos: before 20250123 (fixed in 20250123)

Published 2025-01-15. Last modified 2026-06-29.