rsync: Multiple Vulnerabilities — GLSA 202501-01 Multiple vulnerabilities have been discovered in rsync, the worst of which could lead to arbitrary code execution. Affected packages Package net-misc/rsync on all architectures Affected versions < 3.3.0-r2 Unaffected versions >= 3.3.0-r2 Background rsync is a server and client utility that provides fast incremental file transfers. It is used to efficiently synchronize files between hosts and is used by emerge to fetch Gentoo's Portage tree. Description Multiple vulnerabilities have been discovered in rsync. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All rsync users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.3.0-r2" References CVE-2024-12084 CVE-2024-12085 CVE-2024-12086 CVE-2024-12087 CVE-2024-12088 CVE-2024-12747