Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-12086
Rsync: rsync server leaks arbitrary client files
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N C H N N 6.8 .0183 78.1 —
AFFECTED
Product Versions Fixed
rsync unspecified —
Red Hat Enterprise Linux 10 unspecified 0:3.4.1-2.el10
Red Hat Enterprise Linux 9 unspecified 0:3.2.5-7.el9_8
Red Hat Enterprise Linux 9 unspecified 0:3.2.5-7.el9_8
Red Hat Enterprise Linux 9.6 Extended Update Support unspecified 0:3.2.5-3.el9_6.1
Red Hat Discovery 2 unspecified 1782166952
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 7 unspecified —
Red Hat Enterprise Linux 8 unspecified —
Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE
Dec 3 Reserved by redhat
Jan 14 Published (CNA: redhat)
Aug 21 RESCORED — CVE-2024-12086 (rsync). CVSS 6.1 → 6.8 (NVD).
Description
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| December 3, 2024 | Reserved | Reserved by redhat |
| January 14, 2025 | Published | Published (CNA: redhat) |
| August 21, 2026 | RESCORED | RESCORED — CVE-2024-12086 (rsync). CVSS 6.1 → 6.8 (NVD). |
Affected
Affected products and packages — 10 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| — | rsync | — | — | — |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:3.4.1-2.el10 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:3.2.5-7.el9_8 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:3.2.5-7.el9_8 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | — | — | 0:3.2.5-3.el9_6.1 |
| Red Hat | Red Hat Discovery 2 | — | — | 1782166952 |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-12086 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.