Off-by-one in Gnome GLib - CVE-2024-52533
Published: November 15, 2024 / Updated: May 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an off-by-one error in gio/gsocks4aproxy.c when handling responses from SOCKS4 proxy. A remote attacker can trick the victim into connecting to a malicious SOCKS4 proxy server, trigger an off-by-one error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Observability with Instana
IBM Sterling Connect:Direct Web Services
IBM Power Hardware Management Console (HMC)
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Splunk Operator for Kubernetes Add-on
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
App Connect Enterprise Certified Container
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
PowerStore 500T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 9200T
PowerStore 9000T
PowerStore 3200Q
PowerStore 3200T
PowerStore 5000T
PowerStore 7000T
PowerStore 5200T
PowerStoreT OS
Precision 7920 Rack
Precision 7920 XL Rack
Cloud Tiering Appliance
SmartFabric Manager
RSA Authentication Manager
iDRAC9
Storage Defender – Data Protect
Storage Virtualize
Total Storage Service Console (TSSC) / TS4500 IMC
Robotic Process Automation for Cloud Pak
OpenManage Network Integration (OMNI)
Storage Resource Manager
Dell EMC VxRail Appliance
IBM Qradar SIEM
Dell Data Lakehouse
Dell Enterprise SONiC Distribution
IBM QRadar Network Packet Capture
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libglib2.0-0 (Ubuntu package)
libglib2.0-bin (Ubuntu package)
libgio-2_0-0
libgio-2_0-0-debuginfo
libgmodule-2_0-0
glib2-devel
glib2-devel-debuginfo
libgobject-2_0-0-debuginfo
libgthread-2_0-0
glib2-tools
glib2-tools-debuginfo
libgthread-2_0-0-debuginfo
libglib-2_0-0-debuginfo
libgobject-2_0-0
libgmodule-2_0-0-debuginfo
glib2-debugsource
libglib-2_0-0
libgobject-2_0-0-debuginfo-32bit
glib2-lang
libgio-2_0-0-debuginfo-32bit
libgmodule-2_0-0-32bit
libgthread-2_0-0-32bit
libgobject-2_0-0-32bit
libgthread-2_0-0-debuginfo-32bit
libgmodule-2_0-0-debuginfo-32bit
libglib-2_0-0-32bit
libglib-2_0-0-debuginfo-32bit
libgio-2_0-0-32bit
glib2 (Red Hat package)
libgio-2_0-0-32bit-debuginfo
libgmodule-2_0-0-32bit-debuginfo
libgobject-2_0-0-32bit-debuginfo
libglib-2_0-0-32bit-debuginfo
glib2-debuginfo
glib2
glib2-help
glib2-tests
glib2-static
glib2-doc
gio-branding-upstream
libgmodule-2_0-0-64bit-debuginfo
libgthread-2_0-0-64bit-debuginfo
libgobject-2_0-0-64bit-debuginfo
libgthread-2_0-0-64bit
libgio-2_0-0-64bit-debuginfo
glib2-devel-64bit
glib2-devel-64bit-debuginfo
libglib-2_0-0-64bit
libgobject-2_0-0-64bit
glib2-tools-64bit-debuginfo
glib2-tools-64bit
libgio-2_0-0-64bit
libgmodule-2_0-0-64bit
libglib-2_0-0-64bit-debuginfo
glib2-tests-devel-debuginfo
glib2-tests-devel
glib2-tools-32bit-debuginfo
glib2-tools-32bit
libgthread-2_0-0-32bit-debuginfo
glib2-devel-32bit-debuginfo
glib2-devel-32bit
glib2-devel-static
mingw-glib2 (Red Hat package)
libglib2.0-0t64 (Ubuntu package)
mingw-glib2
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
Red Hat Ceph Storage
IBM CICS TX Advanced
How to mitigate CVE-2024-52533
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
SmartFabric Manager - update to 1.2.0
IBM Observability with Instana - update to 1.0.307
Storage Defender – Data Protect - update to 2.1.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.14.0.2, 6.4.0.3.0.2
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320, 8.321
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 14
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
RSA Authentication Manager - update to 8.7 SP2 Patch 6
IBM API Connect - update to 10.0.8.5
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.5, 30.0.1
libglib2.0-0 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.8, 2.72.4-0ubuntu2.4
libglib2.0-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.8, 2.72.4-0ubuntu2.4, 2.80.0-6ubuntu3.2
Red Hat OpenShift Serverless - update to 1
Dell Data Lakehouse - update to 1.4.0.0
Ansible Automation Platform - update to 2.5
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.4
libgio-2_0-0 - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgio-2_0-0-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgmodule-2_0-0 - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0 - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0 - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgmodule-2_0-0-debuginfo - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-debugsource - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0 - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-debuginfo-32bit - update to 2.48.2-12.43.1
glib2-lang - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgio-2_0-0-debuginfo-32bit - update to 2.48.2-12.43.1
libgmodule-2_0-0-32bit - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-32bit - addressed in versions 2.48.2-12.43.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-32bit - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-debuginfo-32bit - update to 2.48.2-12.43.1
libgmodule-2_0-0-debuginfo-32bit - update to 2.48.2-12.43.1
libglib-2_0-0-32bit - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0-debuginfo-32bit - update to 2.48.2-12.43.1
libgio-2_0-0-32bit - addressed in versions 2.48.2-12.43.1, 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2 (Red Hat package) - addressed in versions 2.56.4-10.el8_4.2, 2.56.4-166.el8_10, 2.68.4-5.el9_0.2, 2.68.4-7.el9_2.2, 2.68.4-14.el9_4.3, 2.68.4-16.el9_6.2
libgio-2_0-0-32bit-debuginfo - addressed in versions 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgmodule-2_0-0-32bit-debuginfo - addressed in versions 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-32bit-debuginfo - addressed in versions 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0-32bit-debuginfo - addressed in versions 2.62.6-150200.3.24.1, 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-debuginfo - addressed in versions 2.66.8-17, 2.72.2-19, 2.78.3-6
glib2 - addressed in versions 2.66.8-17, 2.72.2-19, 2.78.3-6
glib2-debugsource - addressed in versions 2.66.8-17, 2.72.2-19, 2.78.3-6
glib2-devel - addressed in versions 2.66.8-17, 2.72.2-19, 2.78.3-6
glib2-help - addressed in versions 2.66.8-17, 2.72.2-19, 2.78.3-6
glib2-tests - addressed in versions 2.68.4-16.0.1, 2.78.3-4
glib2-static - addressed in versions 2.68.4-16.0.1, 2.78.3-4
glib2-devel - addressed in versions 2.68.4-16.0.1, 2.78.3-4
glib2 - addressed in versions 2.68.4-16.0.1, 2.78.3-4
glib2-doc - addressed in versions 2.68.4-16.0.1, 2.78.3-4
gio-branding-upstream - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgmodule-2_0-0-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgio-2_0-0-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgobject-2_0-0-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgio-2_0-0-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgmodule-2_0-0-64bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libglib-2_0-0-64bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tests-devel-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-doc - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tests-devel - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools-32bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-tools-32bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
libgthread-2_0-0-32bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-32bit-debuginfo - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-32bit - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-devel-static - addressed in versions 2.70.5-150400.3.17.1, 2.78.6-150600.4.8.1
glib2-static - addressed in versions 2.72.2-19, 2.78.3-6
glib2-tests - addressed in versions 2.72.2-19, 2.78.3-6
mingw-glib2 (Red Hat package) - update to 2.78.6-2.el9
libglib2.0-0t64 (Ubuntu package) - update to 2.80.0-6ubuntu3.2
mingw-glib2 - addressed in versions 2.82.2-1.fc40, 2.82.2-1.fc41
Splunk Operator for Kubernetes Add-on - update to 3.0.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
OpenManage Network Integration (OMNI) - update to 3.7
PowerStoreT OS - update to 4.0.1.3-2494147
Dell Enterprise SONiC Distribution - update to 4.4.2
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.14.54, 4.14.55, 4.15.56, 4.16.45, 4.17.37, 4.18.21, 4.19.6, 4.19.7
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Dell Secure Connect Gateway - update to 5.28.00.14
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
Precision 7920 XL Rack - update to 7.00.00.181
Red Hat Ceph Storage - update to 7.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix37
App Connect Enterprise Certified Container - update to 12.8.0
Cloud Tiering Appliance - update to 13.2.0.2.33
External References
Related Security Bulletins
- Remote code execution in GNOME GLib
- openEuler 20.03 LTS SP4 update for glib2
- openEuler 24.03 LTS update for glib2
- Fedora 41 update for mingw-glib2
- Fedora 40 update for mingw-glib2
- Ubuntu update for glib2.0
- SUSE update for glib2
- openEuler 22.03 LTS SP1 update for glib2
- openEuler 22.03 LTS SP3 update for glib2
- openEuler 22.03 LTS SP4 update for glib2
- SUSE update for glib2
- SUSE update for glib2
- SUSE update for glib2
- SUSE update for glib2
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Red Hat Enterprise Linux 9 update for mingw-glib2
- Dell SmartFabric Manager update for third-party components
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell VxRail Appliance 7.x
- Dell VxRail Appliance 8.x update for third-party components
- Multiple vulnerabilities in IBM CICS TX Advanced
- RSA Authentication Manager update for third-party components
- Anolis OS update for glib2
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Dell Cloud Tiering Appliance/VE update for third-party components
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell iDRAC9
- Dell Data Lakehouse update for third-party components
- Multiple vulnerabilities in Dell Precision Rack
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Red Hat Enterprise Linux 9 update for glib2
- Red Hat Enterprise Linux 8 update for glib2
- Red Hat Enterprise Linux 9 update for glib2
- Red Hat Enterprise Linux 9 update for glib2
- Anolis OS update for glib2
- Red Hat Enterprise Linux 9 update for glib2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Sterling Connect:Direct Web Services
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Red Hat Enterprise Linux 8 update for glib2
- Multiple vulnerabilities in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Splunk Operator for Kubernetes Add-on update for third-party components
- Multiple vulnerabilities in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- Multiple vulnerabilities in IBM Storage Virtualize
- IBM QRadar Network Packet Capture update for GNOME GLib
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in IBM Observability with Instana