Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:2600 - Security Advisory
Issued:
2025-03-11
Updated:
2025-03-11

RHSA-2025:2600 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: rsync security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for rsync is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

  • rsync: Path traversal vulnerability in rsync (CVE-2024-12087)
  • rsync: --safe-links option bypass leads to path traversal (CVE-2024-12088)
  • rsync: Race Condition in rsync Handling Symbolic Links (CVE-2024-12747)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2330672 - CVE-2024-12087 rsync: Path traversal vulnerability in rsync
  • BZ - 2330676 - CVE-2024-12088 rsync: --safe-links option bypass leads to path traversal
  • BZ - 2332968 - CVE-2024-12747 rsync: Race Condition in rsync Handling Symbolic Links

CVEs

  • CVE-2024-12087
  • CVE-2024-12088
  • CVE-2024-12747

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
rsync-3.1.3-21.el8_10.src.rpm SHA-256: 8dd8cd91786a1a30835e61c75f2f56b0449680583cff5be4e396fd82bfaab7c1
x86_64
rsync-3.1.3-21.el8_10.x86_64.rpm SHA-256: c65fc8397e47b5c9a3e3ca8b1aca7136a1534ecbfb76884bdc0dde075e1f990b
rsync-daemon-3.1.3-21.el8_10.noarch.rpm SHA-256: 118b594fdb29cc924235f845b81d1f91e8fdac49ae999aedf82e6244d8480975
rsync-debuginfo-3.1.3-21.el8_10.x86_64.rpm SHA-256: 1e32c0b26b534e6b277c2afdac06ad52b55fb6b3bba0be1e76f95beedd318fde
rsync-debugsource-3.1.3-21.el8_10.x86_64.rpm SHA-256: bda46997c9c38c9ae3bd26deacfdc3c4f2bf6e2ef5ba43ecd7db40f2263df022

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
rsync-3.1.3-21.el8_10.src.rpm SHA-256: 8dd8cd91786a1a30835e61c75f2f56b0449680583cff5be4e396fd82bfaab7c1
s390x
rsync-3.1.3-21.el8_10.s390x.rpm SHA-256: a96c06ec291a0246b8b060b1c2744015e0d3b0ad2f2785adb216ca60e1c6244e
rsync-daemon-3.1.3-21.el8_10.noarch.rpm SHA-256: 118b594fdb29cc924235f845b81d1f91e8fdac49ae999aedf82e6244d8480975
rsync-debuginfo-3.1.3-21.el8_10.s390x.rpm SHA-256: 9fbfb74bfa672afe42b997521added0d6641fa15742f7c08a7f5a4def11e0e4f
rsync-debugsource-3.1.3-21.el8_10.s390x.rpm SHA-256: 708deea20191b65db7b2ceb48faf6dec56c99c4bd4010b1b9de3bb945df25d67

Red Hat Enterprise Linux for Power, little endian 8

SRPM
rsync-3.1.3-21.el8_10.src.rpm SHA-256: 8dd8cd91786a1a30835e61c75f2f56b0449680583cff5be4e396fd82bfaab7c1
ppc64le
rsync-3.1.3-21.el8_10.ppc64le.rpm SHA-256: 13fc835eb33dbf991d34cc204f79fb84938176ea53442073187178818823e373
rsync-daemon-3.1.3-21.el8_10.noarch.rpm SHA-256: 118b594fdb29cc924235f845b81d1f91e8fdac49ae999aedf82e6244d8480975
rsync-debuginfo-3.1.3-21.el8_10.ppc64le.rpm SHA-256: 64c8072255cf56fa809e0f898556c5fc1ffb42bd5df39bfed371fe27a8df9f98
rsync-debugsource-3.1.3-21.el8_10.ppc64le.rpm SHA-256: 679ed32cf3d28acb7dae457b35c1898b1bed07add4fb0b83439dcc20c5716ca1

Red Hat Enterprise Linux for ARM 64 8

SRPM
rsync-3.1.3-21.el8_10.src.rpm SHA-256: 8dd8cd91786a1a30835e61c75f2f56b0449680583cff5be4e396fd82bfaab7c1
aarch64
rsync-3.1.3-21.el8_10.aarch64.rpm SHA-256: c2abdc201cedd3e1831955ae628c644ab670214126697695c77657edbbeaecb2
rsync-daemon-3.1.3-21.el8_10.noarch.rpm SHA-256: 118b594fdb29cc924235f845b81d1f91e8fdac49ae999aedf82e6244d8480975
rsync-debuginfo-3.1.3-21.el8_10.aarch64.rpm SHA-256: 3667970194b7a24635cd4a679629f42bbb8c79da7c8b4c030de065f94709d652
rsync-debugsource-3.1.3-21.el8_10.aarch64.rpm SHA-256: 85e9d762f8731b38492610dd3c360ed492487c873076cf6e6bea68ee82021c72

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility