Wind River Support Network

HomeDefectsLIN1021-12577
Fixed

LIN1021-12577 : Security Advisory - rsync - CVE-2024-12088

Created: Dec 10, 2024    Updated: May 25, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

https://nvd.nist.gov/vuln/detail/CVE-2024-12088

CVEs


Live chat
Online