CVE Vulnerabilities

CVE-2024-12085

Use of Uninitialized Resource

Published: Jan 14, 2025 | Modified: Aug 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Rsync Samba * 3.3.0 (excluding)
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION RedHat rsync-0:3.0.6-12.el6_10.1 *
Red Hat Enterprise Linux 7 Extended Lifecycle Support RedHat rsync-0:3.1.2-12.el7_9.1 *
Red Hat Enterprise Linux 8 RedHat rsync-0:3.1.3-20.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat rsync-0:3.1.3-7.el8_2.3 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat rsync-0:3.1.3-12.el8_4.3 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat rsync-0:3.1.3-12.el8_4.3 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat rsync-0:3.1.3-12.el8_4.3 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat rsync-0:3.1.3-14.el8_6.6 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat rsync-0:3.1.3-14.el8_6.6 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat rsync-0:3.1.3-14.el8_6.6 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat rsync-0:3.1.3-20.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat rsync-0:3.2.3-20.el9_5.1 *
Red Hat Enterprise Linux 9 RedHat rsync-0:3.2.3-20.el9_5.1 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat rsync-0:3.2.3-9.el9_0.3 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat rsync-0:3.2.3-19.el9_2.1 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat rsync-0:3.2.3-19.el9_4.1 *
Red Hat OpenShift Container Platform 4.12 RedHat rhcos-412.86.202502100314-0 *
Red Hat OpenShift Container Platform 4.13 RedHat rhcos-413.92.202503112237-0 *
Red Hat OpenShift Container Platform 4.14 RedHat rhcos-414.92.202502111902-0 *
Red Hat OpenShift Container Platform 4.15 RedHat rhcos-415.92.202501281917-0 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ansible-rhel9-operator:v4.16.0-202501311735.p0.g2cb0020.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-helm-rhel9-operator:v4.16.0-202501311933.p0.g4246d04.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-operator-sdk-rhel9:v4.16.0-202501311605.p0.g4246d04.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat rhcos-417.94.202502051822-0 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/cluster-logging-operator-bundle:v5.8.17-22 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/cluster-logging-rhel9-operator:v5.8.17-10 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch6-rhel9:v6.8.1-454 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-operator-bundle:v5.8.17-17 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-537 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/elasticsearch-rhel9-operator:v5.8.17-4 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-339 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/fluentd-rhel9:v5.8.17-4 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-320 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-curator5-rhel9:v5.8.1-552 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.3.2-9 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/logging-view-plugin-rhel9:v5.8.17-5 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/loki-operator-bundle:v5.8.17-12 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/loki-rhel9-operator:v5.8.17-5 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/lokistack-gateway-rhel9:v0.1.0-725 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/opa-openshift-rhel9:v0.1.0-342 *
RHOL-5.8-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.28.1-88 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/cluster-logging-operator-bundle:v5.9.11-25 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/cluster-logging-rhel9-operator:v5.9.11-11 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-340 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/fluentd-rhel9:v5.9.11-5 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-321 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.3.2-8 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/logging-view-plugin-rhel9:v5.9.11-6 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/loki-operator-bundle:v5.9.11-9 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/loki-rhel9-operator:v5.9.11-4 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/lokistack-gateway-rhel9:v0.1.0-724 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/opa-openshift-rhel9:v0.1.0-341 *
RHOL-5.9-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.34.1-30 *
Rsync Ubuntu devel *
Rsync Ubuntu esm-infra-legacy/trusty *
Rsync Ubuntu esm-infra/bionic *
Rsync Ubuntu esm-infra/xenial *
Rsync Ubuntu focal *
Rsync Ubuntu jammy *
Rsync Ubuntu noble *
Rsync Ubuntu oracular *
Rsync Ubuntu trusty/esm *
Rsync Ubuntu upstream *

Potential Mitigations

References