A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rsync-daemonUpgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Alpine Linux | — | Upgrade rsync | Aug 8, 2025 | Jan 14, 2025 |
| Amazon Linux Ami 2 | — | Upgrade rsync-debuginfoUpgrade rsync | Jan 15, 2025 | Jan 15, 2025 |
| Amazon_linux | — | Upgrade rsync | Jan 18, 2025 | Jan 14, 2025 |
| Amazon_linux_2023 | — | Upgrade rsync-daemonUpgrade rsync-debugsourceUpgrade rsync-debuginfoUpgrade rsync | Feb 17, 2025 | Jan 14, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 14, 2025 |
| Aruba Aos Cx | — | To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Aruba Networking AOS-CX to one of the following versions (as applicable):
- AOS-CX 10.16.xxxx: AOS-CX 10.16.1006 and above
- AOS-CX 10.15.xxxx: AOS-CX 10.15.1030 and above
- AOS-CX 10.14.xxxx: AOS-CX 10.14.1060 and above
- AOS-CX 10.13.xxxx: AOS-CX 10.13.1101 and above
- AOS-CX 10.10.xxxx: AOS-CX 10.10.1170 and above
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch software branches that have reached their End of Maintenance (EoM) milestone.
For more information about HPE Aruba Networking End of Life policy please visit: https://www.hpe.com/psnow/doc/a00143052enw | Nov 28, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Dell Powerstore Dsa2025223 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 27, 2025 |
| Freebsd | — | Upgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Jan 16, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade rsync | Mar 18, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade rsync | Apr 11, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade rsync | Mar 19, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade rsync | Apr 1, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp9 | — | Upgrade rsync | Mar 18, 2025 | Jan 14, 2025 |
| Oracle_linux | — | Upgrade rsyncUpgrade rsync-daemon | Jan 15, 2025 | Jan 14, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Feb 13, 2025 | Jan 14, 2025 |
| Redhat_linux | — | Upgrade rsync-daemonUpgrade rsyncUpgrade rsync-debugsourceUpgrade rsync-debuginfo | Jan 16, 2025 | Jan 14, 2025 |
| Rocky_linux | — | Upgrade rsyncUpgrade rsync-debugsourceUpgrade rsync-debuginfo | Jan 20, 2025 | Jan 14, 2025 |
| Suse | — | Upgrade rsync | Jan 20, 2025 | Jan 14, 2025 |
| Ubuntu | — | Upgrade rsync (Ubuntu Pro)Upgrade rsync | Jan 15, 2025 | Jan 14, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub