Wind River Support Network

HomeDefectsLIN1021-12574
Fixed

LIN1021-12574 : Security Advisory - rsync - CVE-2024-12085

Created: Dec 10, 2024    Updated: May 25, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

https://nvd.nist.gov/vuln/detail/CVE-2024-12085

CVEs


Live chat
Online