A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rsync | Aug 8, 2025 | Jan 15, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 15, 2025 |
| Aruba Aos Cx | — | To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Aruba Networking AOS-CX to one of the following versions (as applicable):
- AOS-CX 10.16.xxxx: AOS-CX 10.16.1006 and above
- AOS-CX 10.15.xxxx: AOS-CX 10.15.1030 and above
- AOS-CX 10.14.xxxx: AOS-CX 10.14.1060 and above
- AOS-CX 10.13.xxxx: AOS-CX 10.13.1101 and above
- AOS-CX 10.10.xxxx: AOS-CX 10.10.1170 and above
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch software branches that have reached their End of Maintenance (EoM) milestone.
For more information about HPE Aruba Networking End of Life policy please visit: https://www.hpe.com/psnow/doc/a00143052enw | Nov 28, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade rsync | Jan 16, 2025 | Jan 16, 2025 |
| Freebsd | — | Upgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Jan 16, 2025 | Jan 15, 2025 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 9.4.11 | Jul 30, 2026 | Jan 15, 2025 |
| Suse | — | Upgrade rsync | Jan 20, 2025 | Jan 15, 2025 |
| Ubuntu | — | Upgrade rsyncUpgrade rsync (Ubuntu Pro) | Jan 15, 2025 | Jan 14, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub