{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/vex/2024/cve-2024-12086-els_os-almalinux9_2esu.json"
      }
    ],
    "title": "Security update on CVE-2024-12086",
    "tracking": {
      "current_release_date": "2026-01-19T22:20:38Z",
      "generator": {
        "date": "2026-01-19T22:20:38Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-12086-ELS_OS-ALMALINUX9.2ESU",
      "initial_release_date": "2024-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2024-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2025-10-08T18:00:15Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2025-10-30T10:56:41Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2025-11-29T11:42:47Z",
          "number": "4",
          "summary": "Update document"
        },
        {
          "date": "2025-12-23T19:08:30Z",
          "number": "5",
          "summary": "Update document"
        },
        {
          "date": "2026-01-19T22:20:38Z",
          "number": "6",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "6"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
                "product": {
                  "name": "rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
                  "product_id": "rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.2.3-19.el9.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
                "product": {
                  "name": "rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
                  "product_id": "rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.2.3-19.el9.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
                  "product_id": "rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.2.3-19.el9.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
                  "product_id": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.2.3-19.el9.tuxcare.els3?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
                  "product_id": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.2.3-19.el9.tuxcare.els2?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
                  "product_id": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.2.3-19.el9.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.2.3-19.el9.x86_64",
                "product": {
                  "name": "rsync-0:3.2.3-19.el9.x86_64",
                  "product_id": "rsync-0:3.2.3-19.el9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/almalinux/rsync@3.2.3-19.el9?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.2.3-19.el9.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.2.3-19.el9.noarch",
                  "product_id": "rsync-daemon-0:3.2.3-19.el9.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/almalinux/rsync-daemon@3.2.3-19.el9?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64"
        },
        "product_reference": "rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64"
        },
        "product_reference": "rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch"
        },
        "product_reference": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch"
        },
        "product_reference": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch"
        },
        "product_reference": "rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.2.3-19.el9.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.x86_64"
        },
        "product_reference": "rsync-0:3.2.3-19.el9.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.2.3-19.el9.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.noarch"
        },
        "product_reference": "rsync-daemon-0:3.2.3-19.el9.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-12086",
      "cwe": {
        "id": "CWE-390",
        "name": "Detection of Error Condition Without Action"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.x86_64",
          "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
          "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
          "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
          "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-12086"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2024-12086",
          "url": "https://access.redhat.com/security/cve/CVE-2024-12086"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2330577",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2330577"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/952657",
          "url": "https://kb.cert.org/vuls/id/952657"
        },
        {
          "category": "external",
          "summary": "https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj",
          "url": "https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250131-0002/",
          "url": "https://security.netapp.com/advisory/ntap-20250131-0002/"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/952657",
          "url": "https://www.kb.cert.org/vuls/id/952657"
        }
      ],
      "release_date": "2025-01-14T18:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Ignored due to low severity",
          "product_ids": [
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.x86_64",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.noarch"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "This flaw only applies during client-to-server transfers and requires the client to connect to an attacker-controlled rsync endpoint; it cannot be triggered by a random network adversary or during pull operations. Even then, exploitation is high‑complexity (a checksum‑oracle, byte‑by‑byte reconstruction) and any disclosure is limited to files readable by the user account running the rsync client, with no integrity or availability impact. In managed enterprise VM/server workflows that sync to authenticated, known endpoints, this malicious‑server precondition is absent, making the practical risk low and appropriate to deprioritize.",
          "product_ids": [
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.x86_64",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:rsync-0:3.2.3-19.el9.x86_64",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els1.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els2.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.tuxcare.els3.noarch",
            "AlmaLinux-9.2:rsync-daemon-0:3.2.3-19.el9.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}