<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz" -->

---
title: Rsync 3.4 Released to Fix Multiple Security Vulnerabilities
description: Rsync version 3.4.0 has been released, addressing six critical security vulnerabilities, including a heap buffer overflow that could lead to remote code...
canonical: https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Rsync 3.4 Released to Fix Multiple Security Vulnerabilities | daily.dev
og:description: Rsync version 3.4.0 has been released, addressing six critical security vulnerabilities, including a heap buffer overflow that could lead to remote code...
og:url: https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz
og:image: https://api.daily.dev/og/posts/EqnjkyXVZ.png
og:image:alt: Rsync 3.4 Released to Fix Multiple Security Vulnerabilities
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rsync 3.4 Released to Fix Multiple Security Vulnerabilities

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Rsync version 3.4.0 has been released, addressing six critical security vulnerabilities, including a heap buffer overflow that could lead to remote code execution. Users, especially those managing critical systems, are urged to update immediately to mitigate risks. For immediate security, mitigations such as disabling SHA support are recommended. Canonical has released updates for all supported Ubuntu versions, and users should verify their Rsync version and apply necessary updates.

## Content

A critical security update for the widely-used file-syncing tool Rsync has been released in version 3.4.0, addressing six major vulnerabilities that could allow remote code execution and unsafe file manipulation. These vulnerabilities, identified by researchers from Google Cloud, include a heap buffer overflow, information leaks, path traversal, and race conditions.

The most critical of these flaws, assigned CVE-2024-12084, involves a heap buffer overflow that could allow attackers with anonymous read access to execute arbitrary code. Additionally, the vulnerabilities lead to issues such as arbitrary file read, creation of unsafe symbolic links, and data exposure.

Canonical has released updates for Rsync across all supported Ubuntu versions to mitigate these security risks. Users are strongly advised to install these updates immediately. To verify if the patch has been applied, users should check the installed version of Rsync using the `dpkg` command and update if necessary.

For those unable to update immediately, mitigations include disabling SHA support and using proper compilation flags. The new version, Rsync 3.4.0, and a subsequent minor bug-fix update 3.4.1, incorporate these security fixes to protect against potential exploits.

Administrators, especially those managing critical systems like Arch Linux mirrors, are urged to upgrade their Rsync daemons and clients to the latest version to safeguard against these vulnerabilities. Users should also monitor software vendor advisories for further updates and apply them promptly to ensure continued security.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#devops](https://daily.dev/tags/devops), [#linux](https://daily.dev/tags/linux)

[View this post on daily.dev](https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Rsync 3.4 Released to Fix Multiple Security Vulnerabilities","url":"https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz"},"datePublished":"2025-01-15T01:55:53.538Z","dateModified":"2025-01-17T22:54:27.858Z","description":"Rsync version 3.4.0 has been released, addressing six critical security vulnerabilities, including a heap buffer overflow that could lead to remote code...","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/rsync-3-4-released-to-fix-multiple-security-vulnerabilities-eqnjkyxvz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,devops,linux","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Rsync 3.4 Released to Fix Multiple Security Vulnerabilities"}]}
```

