Bug 2330539 (CVE-2024-12085)

Summary: CVE-2024-12085 rsync: Info Leak via Uninitialized Stack Contents
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: chaekim, jcantril, kyoshida, rojacob, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2337965, 2337966, 2337970, 2337967, 2337968, 2337969    
Bug Blocks:    
Deadline: 2025-01-14   

Description OSIDB Bzimport 2024-12-05 12:29:53 UTC
The attacker can exploit this vulnerability to leak uninitialized stack data byte by byte, potentially exposing memory locations of critical data.It uses a buffer (sum2) on the stack to store part of the checksum but does not initialize this buffer. An attacker can manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory. This allows an attacker to leak one byte of uninitialized stack data at a time. Over multiple requests, the attacker can leak up to MAX_DIGEST_LEN - 8 bytes of sensitive data, which could help defeat Address Space Layout Randomization (ASLR).

Comment 3 errata-xmlrpc 2025-01-15 06:36:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:0325 https://access.redhat.com/errata/RHSA-2025:0325

Comment 4 errata-xmlrpc 2025-01-15 06:44:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:0324 https://access.redhat.com/errata/RHSA-2025:0324

Comment 5 errata-xmlrpc 2025-01-22 23:45:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:0637 https://access.redhat.com/errata/RHSA-2025:0637

Comment 6 errata-xmlrpc 2025-01-27 01:25:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:0688 https://access.redhat.com/errata/RHSA-2025:0688

Comment 7 errata-xmlrpc 2025-01-27 16:36:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:0714 https://access.redhat.com/errata/RHSA-2025:0714

Comment 8 errata-xmlrpc 2025-01-28 18:46:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:0774 https://access.redhat.com/errata/RHSA-2025:0774

Comment 9 errata-xmlrpc 2025-01-29 08:00:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:0787 https://access.redhat.com/errata/RHSA-2025:0787

Comment 10 errata-xmlrpc 2025-01-29 10:51:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:0790 https://access.redhat.com/errata/RHSA-2025:0790

Comment 11 errata-xmlrpc 2025-01-30 16:57:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2025:0849 https://access.redhat.com/errata/RHSA-2025:0849

Comment 12 errata-xmlrpc 2025-02-03 01:03:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:0884 https://access.redhat.com/errata/RHSA-2025:0884

Comment 13 errata-xmlrpc 2025-02-03 01:05:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:0885 https://access.redhat.com/errata/RHSA-2025:0885

Comment 15 errata-xmlrpc 2025-02-11 11:31:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:1120 https://access.redhat.com/errata/RHSA-2025:1120

Comment 16 errata-xmlrpc 2025-02-12 00:13:39 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2025:1123 https://access.redhat.com/errata/RHSA-2025:1123

Comment 17 errata-xmlrpc 2025-02-12 03:43:26 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2025:1128 https://access.redhat.com/errata/RHSA-2025:1128

Comment 18 errata-xmlrpc 2025-02-12 16:40:15 UTC
This issue has been addressed in the following products:

  RHOL-5.9-RHEL-9

Via RHSA-2025:1227 https://access.redhat.com/errata/RHSA-2025:1227

Comment 19 errata-xmlrpc 2025-02-13 02:11:23 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:1242 https://access.redhat.com/errata/RHSA-2025:1242

Comment 21 errata-xmlrpc 2025-02-19 23:11:03 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:1451 https://access.redhat.com/errata/RHSA-2025:1451

Comment 23 errata-xmlrpc 2025-03-20 07:01:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2025:2701 https://access.redhat.com/errata/RHSA-2025:2701