Vulnerability CVE-2024-52522: Information

Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

Severity: MEDIUM (5.4)
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Published: Nov. 15, 2024
Modified: June 17, 2026
Error type identifier: CWE-59CWE-61CWE-281

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
rclonesisyphus1.69.1-alt11.74.3-alt1ALT-PU-2025-4039-3377561Fixed
rclonesisyphus_riscv641.69.1-alt11.74.3-alt1ALT-PU-2025-4135-1-Fixed
rclonesisyphus_loongarch641.69.1-alt11.74.3-alt1ALT-PU-2025-4070-1-Fixed
rclonep111.69.1-alt11.73.5-alt1ALT-PU-2025-7927-2386738Fixed
rclonep101.69.1-alt11.69.1-alt1ALT-PU-2025-8008-3386739Fixed
rclonec10f21.69.1-alt11.74.3-alt1ALT-PU-2025-4860-4379391Fixed
rclonec9f21.69.1-alt11.69.1-alt1ALT-PU-2025-4862-4379392Fixed

References to Advisories, Solutions, and Tools