Vulnerability CVE-2024-52522: Information
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
Severity: MEDIUM (5.4)
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Published: Nov. 15, 2024
Modified: June 17, 2026
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| rclone | sisyphus | 1.69.1-alt1 | 1.74.3-alt1 | ALT-PU-2025-4039-3 | 377561 | Fixed |
| rclone | sisyphus_riscv64 | 1.69.1-alt1 | 1.74.3-alt1 | ALT-PU-2025-4135-1 | - | Fixed |
| rclone | sisyphus_loongarch64 | 1.69.1-alt1 | 1.74.3-alt1 | ALT-PU-2025-4070-1 | - | Fixed |
| rclone | p11 | 1.69.1-alt1 | 1.73.5-alt1 | ALT-PU-2025-7927-2 | 386738 | Fixed |
| rclone | p10 | 1.69.1-alt1 | 1.69.1-alt1 | ALT-PU-2025-8008-3 | 386739 | Fixed |
| rclone | c10f2 | 1.69.1-alt1 | 1.74.3-alt1 | ALT-PU-2025-4860-4 | 379391 | Fixed |
| rclone | c9f2 | 1.69.1-alt1 | 1.69.1-alt1 | ALT-PU-2025-4862-4 | 379392 | Fixed |