Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighPublic exploit

Path Traversal in rsync --safe-links Handling

IdentifiersCVE-2024-12088CWE-22· Improper Limitation of a Pathname…

CVE-2024-12088 is a client-side rsync path traversal vulnerability caused by improper validation of symbolic link destinations when the rsync client is used with the --safe-links option. According to the provided content, the client fails to properly verify whether a symbolic link destination supplied by a server contains another symbolic link within it. This incomplete symlink validation can allow traversal outside the intended destination directory, resulting in arbitrary file writes outside the desired path. The issue is described as affecting rsync versions 3.3.0 and earlier, and fixes were released in rsync 3.4.1.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

A malicious rsync server can exploit this flaw to cause the client to write files outside the directory the user intended to synchronize into. This can lead to arbitrary file overwrite/write on the client side, potentially enabling corruption of user data, modification of configuration files, placement of attacker-controlled files in sensitive locations accessible to the client process, and follow-on compromise depending on what files can be targeted and the privileges of the rsync client process.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, avoid synchronizing from untrusted or potentially malicious rsync servers, especially in workflows that invoke the client with --safe-links. Limit rsync client execution to low-privilege accounts, restrict write access to sensitive filesystem locations, and isolate synchronization jobs so that unintended writes have minimal impact. More generally, only pull data from trusted servers until patched packages are deployed.

Remediation

Patch, then assume compromise.

Upgrade rsync to a fixed release. The provided content states that the rsync project addressed CVE-2024-12088 in version 3.4.1, and downstream vendors have also shipped patched packages. Where distribution-packaged rsync is used, install the vendor-provided security update rather than relying on an unpatched upstream or backported build.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AlmalinuxAlmalinuxoperating_system
ArchlinuxArch Linuxoperating_system
GentooLinuxoperating_system
HPE Aruba NetworkingManagement Software (Airwave)application
NixosNixosoperating_system
NovellSuse Linuxoperating_system
Red HatDiscoveryapplication
Red HatEnterprise Linuxoperating_system
Red HatEnterprise Linux Eusoperating_system
Red HatEnterprise Linux For Arm 64operating_system
Red HatEnterprise Linux For Arm 64 Eusoperating_system
Red HatEnterprise Linux For Ibm Z Systemsoperating_system
Red HatEnterprise Linux For Ibm Z Systems Eusoperating_system
Red HatEnterprise Linux For Power Little Endianoperating_system
Red HatEnterprise Linux For Power Little Endian Eusoperating_system
Red HatEnterprise Linux Server Ausoperating_system
Red HatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutionsoperating_system
Red HatEnterprise Linux Update Services For Sap Solutionsoperating_system
Red HatOpenshift Container Platformapplication
SambaRsyncapplication
TritondatacenterSmartosoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.