Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2025:0157-1 important: rsync security issues resolved

suse
Calendar Grey January 17, 2025
Dist Suse Esm H88
The security notice from SUSE regarding Rsync highlights several severe vulnerabilities and offers information on patches to mitigate these problems.
* bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 * bsc#1235475

Summary

## This update for rsync fixes the following issues: * CVE-2024-12085: leak of uninitialized stack data on the server leading to possible ASLR bypass. (bsc#1234101) * CVE-2024-12086: leak of a client machine's file contents through the processing of checksum data. (bsc#1234102) * CVE-2024-12087: arbitrary file overwrite possible on clients when symlink syncing is enabled. (bsc#1234103) * CVE-2024-12088: bypass of the --safe-links flag may allow the placement of unsafe symlinks in a client. (bsc#1234104) * CVE-2024-12747: Fixed a race condition in rsync handling symbolic links. (bsc#1235475) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

* bsc#1234101

* bsc#1234102

* bsc#1234103

* bsc#1234104

* bsc#1235475

* bsc#1235895

Cross-

* CVE-2024-12085

* CVE-2024-12086

* CVE-2024-12087

* CVE-2024-12088

* CVE-2024-12747

CVSS scores:

* CVE-2024-12085 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2024-12085 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

* CVE-2024-12085 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2024-12086 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2024-12086 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

* CVE-2024-12086 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

* CVE-2024-12087 ( SUSE ): 8.6

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0157-1
Release Date: 2025-01-17T11:59:45Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here