CVE-2024-12084General(almalinux / almalinux)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • almalinux
  • arch_linux
  • enterprise_linux
  • linux

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 5 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-30); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Products
almalinuxarch_linuxenterprise_linuxlinuxnixosrsyncsmartossuse_linux

5 versions affected across 8 products

Deep dive

Activity timeline6 mentions / 3d
01122Mentions · 2026-01-30: 2Mentions · 2026-01-31: 2Mentions · 2026-02-01: 2Technical Details · 2026-01-30: 201-3001-3102-01
Signal classification2 categories
General
583.3%
Disclosure
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1General1
2026-01-312
General2
2026-02-012
General2
Full discourse6 posts
  • Alex Matrosov@matrosov
    General

    Code-level detections on compiled code are hard. CVE-2024-12084 is a great showcase for VulHunt’s semantic-driven vulnerability detection. It doesn’t just find the right artifacts, it proves their state and reachability, providing enough evidence to show the issue exists. https://t.co/uCMVeHTqz6

    Post summary

    The tweet highlights a new vulnerability detection technique for CVE-2024-12084, confirming the issue exists but offers no PoC, exploit, or patch information.

    37239156.4K
    18.9K followersView on X
  • BINARLY🔬@binarly_io
    General

    🪄✨New REsearch: detecting CVE-2024-12084 in rsync from binaries using VulHunt rules. Good example of “semantic” vuln matching beyond YARA/byte sigs or sloppy version strings. https://www.binarly.io/blog/vulhunt-in-practice-detecting-a-remote-code-execution-vulnerability-in-rsync

    Post summary

    The post announces a new research method that detects CVE‑2024‑12084 using semantic matching via VulHunt rules, but does not discuss exploitation, patches, or false positives.

    31413199.3K
    4.2K followersView on X
  • BINARLY🔬@binarly_io
    Disclosure

    CVE-2024-12084 vulnerability core: rsync checksum structs include sum2[SUM_LENGTH] where SUM_LENGTH=16. But protocol negotiation sets s2length (attacker-controlled).

    Post summary

    The passage describes the core technical flaw of CVE‑2024‑12084, detailing how rsync checksum handling can be abused due to attacker‑controlled parameters.

    10021385
    4.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-33217 2 - CVE-2023-41064 3 - CVE-2026-24423 4 - CVE-2026-1281 5 - CVE-2024-12084 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top 5 trending CVEs without offering any additional context, technical detail, or actionable information.

    00021303
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-43529 2 - CVE-2026-1281 3 - CVE-2026-24858 4 - CVE-2024-12084 5 - CVE-2026-24061 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists trending CVEs without providing any additional details or claims about exploitation, patches, or technical specifics.

    00010303
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @binarly_io You now can see the full details about this CVE on https://vulntracker.io/cves/CVE-2024-12084

    Post summary

    The tweet simply directs readers to a website for more information on CVE-2024-12084 without providing further details or discussing exploitation, mitigation, or false positives.

    0000064
    335 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSalmalinuxalmalinux10.0--
OSarchlinuxarch_linux---
OSgentoolinux---
OSnixosnixos---
OSnixosnixos24.11--
OSnovellsuse_linux---
OSredhatenterprise_linux10.0--
Appsambarsync3.2.7--
Appsambarsync3.3.0--
OStritondatacentersmartos---

Explore more