Rsync: path traversal vulnerability in rsync
Published Jan 14, 2025
7.5
HIGHCVSS 3.1
EPSS 2.31%
Description
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
Configuration 2
Configuration 3
- n/a
Configuration 6
- n/a
Configuration 7
- < 20250123
Configuration 8
- 8.0
- 9.0
- 9.6
- 8.0_aarch64
- 9.0_aarch64
- 9.6_aarch64
- 8.0_s390x
- 9.0_s390x
- 9.6_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 9.6_ppc64le
- 9.6
- 9.6_ppc64le
- 9.6
No data.
Red Hat Discovery 1.14
discovery/discovery-ui-rhel9:1.14.2-1748467619
Fixed · RHSA-2025:8385
Red Hat Enterprise Linux 10
rsync-0:3.4.1-2.el10
Fixed · RHBA-2025:6470
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
rsync-0:3.0.6-12.el6_10.2
Fixed · RHSA-2025:23416
Red Hat Enterprise Linux 7 Extended Lifecycle Support
rsync-0:3.1.2-12.el7_9.2
Fixed · RHSA-2025:23415
Red Hat Enterprise Linux 8
rsync-0:3.1.3-21.el8_10
Fixed · RHSA-2025:2600
Red Hat Enterprise Linux 8.2 Advanced Update Support
rsync-0:3.1.3-7.el8_2.6
Fixed · RHSA-2025:23842
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
rsync-0:3.1.3-12.el8_4.6
Fixed · RHSA-2025:23853
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
rsync-0:3.1.3-12.el8_4.6
Fixed · RHSA-2025:23853
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
rsync-0:3.1.3-14.el8_6.9
Fixed · RHSA-2025:23854
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
rsync-0:3.1.3-14.el8_6.9
Fixed · RHSA-2025:23854
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
rsync-0:3.1.3-14.el8_6.9
Fixed · RHSA-2025:23854
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
rsync-0:3.1.3-20.el8_8.4
Fixed · RHSA-2025:23858
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
rsync-0:3.1.3-20.el8_8.4
Fixed · RHSA-2025:23858
Red Hat Enterprise Linux 9
rsync-0:3.2.5-3.el9
Fixed · RHSA-2025:7050
Red Hat Enterprise Linux 9
rsync-0:3.2.5-3.el9
Fixed · RHSA-2025:7050
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
rsync-0:3.2.3-9.el9_0.4
Fixed · RHSA-2025:23407
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
rsync-0:3.2.3-19.el9_2.2
Fixed · RHSA-2025:23235
Red Hat Enterprise Linux 9.4 Extended Update Support
rsync-0:3.2.3-19.el9_4.2
Fixed · RHSA-2025:23154
Red Hat OpenShift Container Platform 4
rhcos
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 1.14 | discovery/discovery-ui-rhel9:1.14.2-1748467619 | Fixed | RHSA-2025:8385 |
| Red Hat Enterprise Linux 10 | rsync-0:3.4.1-2.el10 | Fixed | RHBA-2025:6470 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | rsync-0:3.0.6-12.el6_10.2 | Fixed | RHSA-2025:23416 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | rsync-0:3.1.2-12.el7_9.2 | Fixed | RHSA-2025:23415 |
| Red Hat Enterprise Linux 8 | rsync-0:3.1.3-21.el8_10 | Fixed | RHSA-2025:2600 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | rsync-0:3.1.3-7.el8_2.6 | Fixed | RHSA-2025:23842 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | rsync-0:3.1.3-12.el8_4.6 | Fixed | RHSA-2025:23853 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | rsync-0:3.1.3-12.el8_4.6 | Fixed | RHSA-2025:23853 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | rsync-0:3.1.3-14.el8_6.9 | Fixed | RHSA-2025:23854 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | rsync-0:3.1.3-14.el8_6.9 | Fixed | RHSA-2025:23854 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | rsync-0:3.1.3-14.el8_6.9 | Fixed | RHSA-2025:23854 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | rsync-0:3.1.3-20.el8_8.4 | Fixed | RHSA-2025:23858 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | rsync-0:3.1.3-20.el8_8.4 | Fixed | RHSA-2025:23858 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.5-3.el9 | Fixed | RHSA-2025:7050 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.5-3.el9 | Fixed | RHSA-2025:7050 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | rsync-0:3.2.3-9.el9_0.4 | Fixed | RHSA-2025:23407 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | rsync-0:3.2.3-19.el9_2.2 | Fixed | RHSA-2025:23235 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | rsync-0:3.2.3-19.el9_4.2 | Fixed | RHSA-2025:23154 |
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
Red Hat rates this flaw to have moderate severity as it depends on specific configurations for the attack to succeed, symbolic link syncing must be enabled (explicitly by providing the `--links` option or implicitly such as with `--archive`) and the client must connect to a malicious or compromised server.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 26, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.31% (0.02307) | 82.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.22% (0.02224) | 80.34th | v5 (v2026.06.15) |
| Apr 21, 2026 | 2.40% (0.02400) | 85.09th | v4 (v2025.03.14) |
| Feb 22, 2026 | 3.69% (0.03692) | 87.69th | v4 (v2025.03.14) |
| Feb 18, 2026 | 0.78% (0.00780) | 73.27th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.98% (0.02981) | 86.04th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.76% (0.05765) | 89.53th | v4 (v2025.03.14) |
| Nov 4, 2025 | 2.55% (0.02551) | 84.95th | v4 (v2025.03.14) |
| Oct 31, 2025 | 1.10% (0.01104) | 77.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.08% (0.00084) | 22.18th | v4 (v2025.03.14) |
| Jan 15, 2025 | 0.04% (0.00045) | 17.61th | v3 (v2023.03.01) |
References (22)
- https://access.redhat.com/errata/RHBA-2025:6470 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23154 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23235 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23407 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23415 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23416 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23842 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23854 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:23858 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:2600 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7050 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:8385 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-12087 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2330672 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj exploitThird Party Advisory
- https://kb.cert.org/vuls/id/952657 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-12087
- https://security.netapp.com/advisory/ntap-20250131-0002/
- https://www.cve.org/CVERecord?id=CVE-2024-12087
- https://www.kb.cert.org/vuls/id/952657
Change history (0)
No recorded changes yet.