• News/
  • https://www.bleepingcomputer.com/news/security/over-660-000-rsync-servers-exposed-to-code-execution-attacks/

Over 660,000 Rsync servers exposed to code execution attacks

BleepingComputer
·
Bill Toulas
·
Published Jan 15, 2025
·
Updated

Over 660,000 exposed Rsync servers are potentially vulnerable to six new vulnerabilities, including a critical-severity heap-buffer overflow flaw that allows remote code execution on servers. Rsync is an open-source file synchronization and data transferring tool valued for its ability to perform incremental transfers, reducing data transfer times and bandwidth usage. It supports local file systems transfers, remote transfers over secure protocols like SSH, and direct file syncing via its own daemon. The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations. The Rsync flaws were discovered by Google Cloud and independent security researchers and can be combined to create powerful exploitation chains that lead to remote system compromise. "In the most severe CVE, an attacker only requires anonymous read access to a rsync server, such as a public mirror, to execute arbitrary code on the machine the server is running on," reads the bulletin published on Openwall. The six flaws are summarized below: The CERT Coordination Center (CERT/CC) issued a bulletin warning about the Rsync flaws, marking Red Hat, Arch, Gentoo, Ubuntu NixOS, AlmaLinux OS Foundation, and the Triton Data Center as impacted. However, many more potentially impacted projects and vendors have not responded yet. "When combined, the first two vulnerabilities (heap buffer overflow and information leak) allo...

Read full article

Affected Software

9 affected components
rsync=3.4.0
Red Hat
Arch
Gentoo
Ubuntu
NixOS
AlmaLinux OS Foundation
Triton Data Center
Open Source Rsync
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are Rsync servers exposed to?

Rsync servers are exposed to six new vulnerabilities, including a critical heap-buffer overflow flaw allowing remote code execution.

2

How many Rsync servers are affected by these vulnerabilities?

Over 660,000 Rsync servers are potentially vulnerable to these attacks.

3

What versions of Rsync are affected by the vulnerabilities?

The vulnerabilities specifically affect Rsync version 3.4.0.

4

Which operating systems are mentioned as having vulnerable Rsync installations?

Operating systems mentioned include Red Hat, Arch, Gentoo, Ubuntu, NixOS, and AlmaLinux.

5

What is the primary risk associated with the identified vulnerabilities in Rsync?

The primary risk is the potential for remote code execution on the exposed servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203