CVE-2024-6655
Description
A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2024-6655 allows library injection into GTK-2/GTK-3 applications via the current working directory when a GTK module is missing from standard paths.
Vulnerability
CVE-2024-6655 is a flaw in the GTK library (both GTK-2 and GTK-3) that permits a library to be injected into a GTK application from the current working directory (CWD) [4]. The bug occurs when a GTK module is requested but is not found in the standard library paths; under these conditions, the system may load a library from the CWD, enabling arbitrary code execution [3][4].
Exploitation
To exploit this vulnerability, an attacker must place a malicious library (e.g., a shared object) in the CWD of a GTK-based application that attempts to load a missing module [4]. The attack does not require authentication but does require the victim to run the application from a directory where the attacker can write or plant files. No special network position is needed, as local file access is sufficient [3].
Impact
If successful, an attacker can inject and execute arbitrary code within the context of the vulnerable GTK application, potentially leading to full system compromise or privilege escalation depending on the application's permissions [4]. The impact is rated as High with a CVSS v3 score of 7.0 [1][2].
Mitigation
GTK-3 version 3.24.43 includes a security fix for this issue, and Red Hat has provided updated packages for Red Hat Enterprise Linux 9 via RHSA-2024:9184 and RHSA-2024:6963 [1][2][4]. GTK-2 is no longer maintained and will not receive an official patch; users are advised to either backport the fix or to avoid running GTK-2 applications from untrusted directories [4].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
79- osv-coords79 versionspkg:rpm/almalinux/gtk3pkg:rpm/almalinux/gtk3-develpkg:rpm/almalinux/gtk3-devel-docspkg:rpm/almalinux/gtk3-immodule-ximpkg:rpm/almalinux/gtk-update-icon-cachepkg:rpm/opensuse/gnome-themes-standard&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/gtk2&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/gtk2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/gtk2&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/gtk2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/gtk3-branding-SLE&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/gtk3&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/gtk3&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/gtk3&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/gtk3&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/gtk3-doc&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/gnome-themes-standard&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/gnome-themes-standard&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/gtk2&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/gtk2&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/gtk2&distro=SUSE%20Manager%20Server%204.3pkg:rpm/suse/gtk3-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/gtk3&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/gtk3&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/gtk3&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/gtk3&distro=SUSE%20Manager%20Server%204.3pkg:rpm/suse/gtk3-doc&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/gtk3-doc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4
< 3.22.30-12.el8_10+ 78 more
- (no CPE)range: < 3.22.30-12.el8_10
- (no CPE)range: < 3.22.30-12.el8_10
- (no CPE)range: < 3.22.30-12.el8_10
- (no CPE)range: < 3.22.30-12.el8_10
- (no CPE)range: < 3.22.30-12.el8_10
- (no CPE)range: < 3.22.3-150000.4.5.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150600.11.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-10.1
- (no CPE)range: < 15.0-150600.21.2.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.38+111-150600.3.3.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.43-1.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.22.3-150000.4.5.1
- (no CPE)range: < 3.22.3-150000.4.5.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150600.11.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150600.11.3.1
- (no CPE)range: < 2.24.31-9.9.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.31-9.9.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.32+67-150200.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.31-9.9.1
- (no CPE)range: < 2.24.31-9.9.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 2.24.33-150400.4.3.1
- (no CPE)range: < 15.0-150600.21.2.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.38+111-150600.3.3.1
- (no CPE)range: < 3.24.38+111-150600.3.3.1
- (no CPE)range: < 3.20.10-17.16.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.20.10-17.16.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.20.10-17.16.1
- (no CPE)range: < 3.24.37+70-6.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.20-150200.3.9.1
- (no CPE)range: < 3.24.34-150400.3.9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.openwall.com/lists/oss-security/2024/09/09/1nvd
- access.redhat.com/errata/RHSA-2024:6963nvd
- access.redhat.com/errata/RHSA-2024:9184nvd
- access.redhat.com/security/cve/CVE-2024-6655nvd
- bugzilla.redhat.com/show_bug.cginvd
- gitlab.gnome.org/GNOME/gtk/-/merge_requests/7361/diffsnvd
- www.openwall.com/lists/oss-security/2024/09/09/1nvd
News mentions
0No linked articles in our index yet.