PT-2024-10126 · Rsync+10 · Rsync+10

Jspelman-Google

+2

·

Published

2024-11-15

·

Updated

2026-01-06

·

CVE-2024-12087

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
The rsync software is affected by a path traversal issue, which arises from the behavior enabled by the --inc-recursive option. This option is default-enabled for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the --inc-recursive option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client. The affected software is rsync, but the specific vulnerable versions are not specified in the given text. An exploit could potentially be used to write malicious files to arbitrary locations on the client's system. #rsync #pathtraversal #remoteserver #maliciousfiles #symlinkverification #deduplicationchecks #increcursiveoption #securityrisk #maliciousserver

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALSA-2025:2600
ALSA-2025:7050
ALT-PU-2025-1240
ALT-PU-2025-1316
ALT-PU-2025-1318
ALT-PU-2025-1320
ALT-PU-2025-1322
AZL-55655
AZL-55682
BDU:2025-00377
CESA-2025_2600
CVE-2024-12087
DLA-4015-1
DLA-4015-2
DSA-5843-1
DSA-5843-2
GHSA-P5PG-X43V-MVQJ
INFSA-2025_2600
INFSA-2025_7050
MGASA-2025-0019
OESA-2025-1060
OESA-2025-1061
OESA-2025-1062
OESA-2025-1063
OESA-2025-1064
OPENSUSE-SU-2025:14665-1
OPENSUSE-SU-2025_0118-1
OPENSUSE-SU-2025_0118-2
OPENSUSE-SU-2025_0122-1
OPENSUSE-SU-2025_0122-2
OPENSUSE-SU-2025_0156-1
OPENSUSE-SU-2025_0165-1
RHSA-2025:23154
RHSA-2025:23235
RHSA-2025:23407
RHSA-2025:23415
RHSA-2025:23416
RHSA-2025:23842
RHSA-2025:23853
RHSA-2025:23854
RHSA-2025:23858
RHSA-2025:2600
RHSA-2025:7050
RHSA-2025_2600
RHSA-2025_7050
SUSE-SU-2025:0156-1
SUSE-SU-2025:0157-1
SUSE-SU-2025:0165-1
SUSE-SU-2025:0166-1
SUSE-SU-2025:20122-1
SUSE-SU-2025:20223-1
SUSE-SU-2026:2038-1
SUSE-SU-2026:2048-1
SUSE-SU-2026:2083-1
SUSE-SU-2026:21726-1
USN-7206-1
USN-7206-2
USN-7206-3
USN-7206-4

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Rsync