CVE-2024-52337

Published Nov 26, 2024

Last updated 2 days ago

Overview

Description
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be inserted into the log. Instead of the 'evil' the attacker could mimic a valid TuneD log line and trick the administrator. The quotes '' are usually used in TuneD logs citing raw user input, so there will always be the ' character ending the spoofed input, and the administrator can easily overlook this. This logged string is later used in logging and in the output of utilities, for example, `tuned-adm get_instances` or other third-party programs that use Tuned's D-Bus interface for such operations.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. Vulnerabilidades en Linux Tuned Daemon CVE-2024-52336 (CVSS 7.8) CVE-2024-52337 (CVSS 5.5) https://t.co/1YvneDk7wQ

    @elhackernet

    2 Dec 2024

    2255 Impressions

    9 Retweets

    30 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-52336 & CVE-2024-52337: Vulnerabilities in Linux Tuned Daemon https://t.co/ECTm09TYlR

    @Dinosn

    2 Dec 2024

    2332 Impressions

    4 Retweets

    11 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-52336 & CVE-2024-52337: Vulnerabilities in Linux Tuned Daemon https://t.co/EJ8DVGCRUl

    @testalways

    2 Dec 2024

    104 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CVE-2024-52336 & CVE-2024-52337: Vulnerabilities in Linux Tuned Daemon Learn about the critical vulnerabilities in #Linux Tuned daemon and the security risks they pose. https://t.co/HEFqbhUIqp

    @the_yellow_fall

    2 Dec 2024

    118 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. 🗣 CVE-2024-52336 & CVE-2024-52337: Vulnerabilities in Linux Tuned Daemon https://t.co/vEHOLDtH8h

    @fridaysecurity

    2 Dec 2024

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. tuned: local root exploit in D-Bus method instance_create and other issues in tuned >= 2.23 (CVE-2024-52336, CVE-2024-52337) by Matthias Gerstner (SUSE) https://t.co/E125oic8Q2 Followup on D-Bus client identification by Simon McVittie (Debian) https://t.co/MBZBJ5rdlN

    @oss_security

    28 Nov 2024

    29 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. CVE-2024-52337 A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of c… https://t.co/fdsSnraGTZ

    @CVEnew

    26 Nov 2024

    411 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes