A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rsyncUpgrade rsync-rrsyncUpgrade rsync-daemon | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade rsync | Aug 8, 2025 | Jan 14, 2025 |
| Amazon Linux Ami 2 | — | Upgrade rsyncUpgrade rsync-debuginfo | Jan 15, 2025 | Jan 15, 2025 |
| Amazon_linux | — | Upgrade rsync | Jan 18, 2025 | Jan 14, 2025 |
| Amazon_linux_2023 | — | Upgrade rsync-debuginfoUpgrade rsync-debugsourceUpgrade rsyncUpgrade rsync-daemon | Feb 17, 2025 | Jan 14, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 14, 2025 |
| Aruba Aos Cx | — | To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Aruba Networking AOS-CX to one of the following versions (as applicable):
- AOS-CX 10.16.xxxx: AOS-CX 10.16.1006 and above
- AOS-CX 10.15.xxxx: AOS-CX 10.15.1030 and above
- AOS-CX 10.14.xxxx: AOS-CX 10.14.1060 and above
- AOS-CX 10.13.xxxx: AOS-CX 10.13.1101 and above
- AOS-CX 10.10.xxxx: AOS-CX 10.10.1170 and above
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch software branches that have reached their End of Maintenance (EoM) milestone.
For more information about HPE Aruba Networking End of Life policy please visit: https://www.hpe.com/psnow/doc/a00143052enw | Nov 28, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Dell Powerstore Dsa2025223 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 27, 2025 |
| Freebsd | — | Upgrade rsync | Jan 16, 2025 | Jan 14, 2025 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | Jan 16, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade rsync | May 13, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade rsync | Apr 11, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade rsync | May 7, 2025 | Jan 14, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade rsync | Jun 11, 2025 | Jan 14, 2025 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jul 2, 2026 | Jul 1, 2026 |
| Redhat_linux | — | Upgrade rsyncUpgrade rsync-rrsyncUpgrade rsync-debugsourceNo solution existsUpgrade rsync-debuginfoUpgrade rsync-daemon | Jul 9, 2025 | Jan 14, 2025 |
| Rocky_linux | — | Upgrade rsync-debugsourceUpgrade rsync-debuginfoUpgrade rsync | Jun 1, 2026 | May 28, 2026 |
| Splunk | — | Upgrade Splunk Universal Forwarder to version 9.4.11 | Jul 30, 2026 | Jan 14, 2025 |
| Suse | — | Upgrade rsync | Jan 20, 2025 | Jan 14, 2025 |
| Ubuntu | — | Upgrade rsyncUpgrade rsync (Ubuntu Pro) | Jan 15, 2025 | Jan 14, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub