PT-2024-9111 · Gnome+9 · Gnome Glib+9

Alan Coopersmith

·

Published

2024-11-11

·

Updated

2026-03-29

·

CVE-2024-52533

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNOME GLib versions prior to 2.82.1
Description: The issue is related to an off-by-one error and resultant buffer overflow in the gio/gsocks4aproxy.c component of GNOME GLib. This occurs because SOCKS4 CONN MSG LEN is not sufficient for a trailing 0 character. The vulnerability is associated with uncontrolled copying of input data, which could allow a remote attacker to cause a denial of service. Despite being marked as critical, exploitation of this issue in real-world scenarios is considered highly unlikely.
Recommendations: For GNOME GLib versions prior to 2.82.1, update to version 2.82.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable gio/gsocks4aproxy.c component until a patch is applied. Avoid using the SOCKS4 CONN MSG LEN variable in affected API endpoints until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0936
ALSA-2025:11140
ALSA-2025:11327
AZL-52608
AZL-52639
BDU:2024-10796
CESA-2025_11327
CVE-2024-52533
DLA-3962-1
INFSA-2025_0936
INFSA-2025_11140
INFSA-2025_11327
MGASA-2024-0386
OESA-2024-2381
OESA-2024-2382
OESA-2024-2435
OESA-2024-2436
OESA-2024-2437
OPENSUSE-SU-2024:14487-1
OPENSUSE-SU-2024_4078-1
OPENSUSE-SU-2024_4254-1
RHSA-2025:0936
RHSA-2025:10855
RHSA-2025:11140
RHSA-2025:11327
RHSA-2025:11373
RHSA-2025:11374
RHSA-2025:12275
RHSA-2025_0936
RHSA-2025_11140
RHSA-2025_11327
RLSA-2025:0936
SUSE-SU-2024:3998-1
SUSE-SU-2024:4051-1
SUSE-SU-2024:4051-2
SUSE-SU-2024:4078-1
SUSE-SU-2024:4254-1
SUSE-SU-2024_3998-1
SUSE-SU-2024_4051-1
SUSE-SU-2024_4051-2
SUSE-SU-2024_4078-1
SUSE-SU-2024_4254-1
SUSE-SU-2025:20095-1
SUSE-SU-2025:20232-1
USN-7114-1

Affected Products

Almalinux
Astra Linux
Centos
Gnome Glib
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu