CVE-2024-52337
Description
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be inserted into the log. Instead of the 'evil' the attacker could mimic a valid TuneD log line and trick the administrator. The quotes '' are usually used in TuneD logs citing raw user input, so there will always be the ' character ending the spoofed input, and the administrator can easily overlook this. This logged string is later used in logging and in the output of utilities, for example, tuned-adm get_instances or other third-party programs that use Tuned's D-Bus interface for such operations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- osv-coords14 versionspkg:rpm/almalinux/tunedpkg:rpm/almalinux/tuned-gtkpkg:rpm/almalinux/tuned-ppdpkg:rpm/almalinux/tuned-profiles-atomicpkg:rpm/almalinux/tuned-profiles-compatpkg:rpm/almalinux/tuned-profiles-cpu-partitioningpkg:rpm/almalinux/tuned-profiles-mssqlpkg:rpm/almalinux/tuned-profiles-oraclepkg:rpm/almalinux/tuned-profiles-postgresqlpkg:rpm/almalinux/tuned-profiles-realtimepkg:rpm/almalinux/tuned-profiles-spectrumscalepkg:rpm/almalinux/tuned-utilspkg:rpm/almalinux/tuned-utils-systemtappkg:rpm/opensuse/tuned&distro=openSUSE%20Tumbleweed
< 2.24.0-2.el9_5.alma.1+ 13 more
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.22.1-5.el8_10
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.24.0-2.el9_5.alma.1
- (no CPE)range: < 2.22.1-5.el8_10
- (no CPE)range: < 2.24.1.0+git.90c24ee-1.1
Patches
Vulnerability mechanics
References
17- access.redhat.com/errata/RHSA-2024:10381nvd
- access.redhat.com/errata/RHSA-2024:10384nvd
- access.redhat.com/errata/RHSA-2024:11161nvd
- access.redhat.com/errata/RHSA-2025:0195nvd
- access.redhat.com/errata/RHSA-2025:0327nvd
- access.redhat.com/errata/RHSA-2025:0368nvd
- access.redhat.com/errata/RHSA-2025:0879nvd
- access.redhat.com/errata/RHSA-2025:0880nvd
- access.redhat.com/errata/RHSA-2025:0881nvd
- access.redhat.com/errata/RHSA-2025:1785nvd
- access.redhat.com/errata/RHSA-2025:1802nvd
- access.redhat.com/security/cve/CVE-2024-52337nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/redhat-performance/tuned/releases/tag/v2.24.1nvd
- security.opensuse.org/2024/11/26/tuned-instance-create.htmlnvd
- www.openwall.com/lists/oss-security/2024/11/28/1nvd
- www.openwall.com/lists/oss-security/2024/11/28/2nvd
News mentions
0No linked articles in our index yet.