Improper Output Neutralization for Logs in tuned (Red Hat package) - CVE-2024-52337

 

Improper Output Neutralization for Logs in tuned (Red Hat package) - CVE-2024-52337

Published: November 28, 2024


Vulnerability identifier: #VU101024
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52337
CWE-ID: CWE-117
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to spoof contents of log files.

The vulnerability exists due to improper input validation when handling log API method parameters from the D-Bus interface. A local user can pass specially crafted input into the log file and spoof its content.



Affected software

tuned (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
tuned
tuned-utils-systemtap
tuned-utils
tuned-profiles-oracle
tuned-profiles-mssql
tuned-profiles-cpu-partitioning
tuned-profiles-compat
tuned-gtk
tuned-profiles-atomic
tuned-profiles-devel
tuned-help
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Fast Datapath (for RHEL for ARM 64)
Red Hat Enterprise Linux Fast Datapath (for IBM z Systems)
Red Hat Enterprise Linux Fast Datapath (for RHEL Server for IBM Power LE)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Real Time - Telecommunications Update Service
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Fast Datapath
IBM Qradar SIEM
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
IBM QRadar Network Packet Capture

How to mitigate CVE-2024-52337

Install updates from vendor's website.

tuned (Red Hat package) - addressed in versions 2.24.1, 2.11.0-5.el7fdp.2, 2.11.0-13.el7_9, 2.20.0-1.el8_4.2, 2.20.0-1.el8_6.2, 2.20.0-2.el8_8.1, 2.20.0-3.el9_2, 2.22.1-3.el9_4, 2.22.1-5.el8_10, 2.24.0-2.el9_5, 2.24.0-2.1.20240819gitc082797f.el8fdp, 2.24.0-2.1.20240819gitc082797f.el9fdp
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF01
tuned - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-utils-systemtap - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-utils - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-oracle - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-mssql - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-cpu-partitioning - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-compat - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-gtk - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-atomic - addressed in versions 2.11.0-13, 2.22.1-5.0.1
tuned-profiles-devel - update to 2.24.1-1
tuned-help - update to 2.24.1-1
tuned - update to 2.24.1-1
tuned - addressed in versions 2.24.1-1.fc39, 2.24.1-1.fc40, 2.24.1-1.fc41
Red Hat OpenShift Container Platform - addressed in versions 4.12.73, 4.14.48
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 12

External References

Related Security Bulletins