PT-2024-9218 · Tuned+6 · Tuned+6

Matthias Gerstner

·

Published

2024-11-07

·

Updated

2025-03-17

·

CVE-2024-52337

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Tuned (affected versions not specified)
Description: A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters, and newlines can be inserted into the log. The attacker could mimic a valid TuneD log line and trick the administrator. The quotes are usually used in TuneD logs citing raw user input, so there will always be the ' character ending the spoofed input, and the administrator can easily overlook this. This logged string is later used in logging and in the output of utilities, for example, tuned-adm get instances or other third-party programs that use Tuned's D-Bus interface for such operations.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:10384
ALSA-2024:11161
ALT-PU-2024-16285
AZL-53546
AZL-53676
BDU:2024-10906
CESA-2024_11161
CVE-2024-52337
INFSA-2024_10384
INFSA-2024_11161
OESA-2024-2530
OPENSUSE-SU-2024:14605-1
RHSA-2024:10381
RHSA-2024:10384
RHSA-2024:11161
RHSA-2024_10384
RHSA-2024_11161
RHSA-2025:0195
RHSA-2025:0327
RHSA-2025:0368
RHSA-2025:0879
RHSA-2025:0880
RHSA-2025:0881
RHSA-2025:1785
RHSA-2025:1802
RLSA-2024:10384
ROSA-SA-2025-2561

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Red Os
Rocky Linux
Tuned