Input validation error in idna - CVE-2024-12224

 

Input validation error in idna - CVE-2024-12224

Published: December 18, 2025


Vulnerability identifier: #VU120191
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-12224
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to an error within the UTS 46 specification when handling Punycode labels that do not produce any non-ASCII output. A remote attacker can construct a specially crafted hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.


Affected software

idna
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Fedora
Server Applications Module
Basesystem Module
Development Tools Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
keylime-agent-rust
awatcher
snpguest
snpguest-debuginfo
sccache-debugsource
sccache-debuginfo
sccache
sevctl
sevctl-debuginfo
fido-device-onboard
sevctl-debugsource
rav1e-debuginfo
librav1e0_6-64bit
librav1e0_6-64bit-debuginfo
librav1e0_6-32bit
librav1e0_6-32bit-debuginfo
rav1e
rav1e-debugsource
librav1e0_6-debuginfo
rav1e-devel
librav1e0_6
gotify-desktop
rustup
rustup-debuginfo
rustup-debugsource
rust-git-interactive-rebase-tool
librsvg-2-2-64bit-debuginfo
gdk-pixbuf-loader-rsvg-64bit
librsvg-2-2-64bit
gdk-pixbuf-loader-rsvg-64bit-debuginfo
gdk-pixbuf-loader-rsvg-32bit
rsvg-thumbnailer
librsvg-2-2-32bit-debuginfo
librsvg-2-2-32bit
gdk-pixbuf-loader-rsvg-32bit-debuginfo
librsvg-devel
rsvg-convert
typelib-1_0-Rsvg-2_0
librsvg-2-2
librsvg-2-2-debuginfo
gdk-pixbuf-loader-rsvg-debuginfo
librsvg-debugsource
gdk-pixbuf-loader-rsvg
librsvg2
librsvg2-devel
librsvg2-tools
rsvg-convert-debuginfo
mirrorlist-server
atuin
rpm-ostree-help
rpm-ostree-devel
rpm-ostree-debugsource
rpm-ostree-debuginfo
rpm-ostree
rpm-ostree-libs

How to mitigate CVE-2024-12224

Install updates from vendor's website.

idna - update to 1.0.0
keylime-agent-rust - addressed in versions 0.2.7-5.fc41, 0.2.8-1.fc42
awatcher - addressed in versions 0.3.1-2.fc41, 0.3.1-2.fc42, 0.3.1-2.fc43
snpguest - update to 0.3.2-150600.3.6.1
snpguest-debuginfo - update to 0.3.2-150600.3.6.1
sccache-debugsource - update to 0.4.2~4-150400.3.6.1
sccache-debuginfo - addressed in versions 0.4.2~4-150400.3.6.1, 0.4.2~4-150600.10.3.1
sccache - addressed in versions 0.4.2~4-150400.3.6.1, 0.4.2~4-150600.10.3.1
sevctl - addressed in versions 0.4.3-150600.4.3.1, 0.6.0-150700.3.3.1
sevctl-debuginfo - addressed in versions 0.4.3-150600.4.3.1, 0.6.0-150700.3.3.1
fido-device-onboard - update to 0.5.1-3.fc41
sevctl-debugsource - update to 0.6.0-150700.3.3.1
rav1e-debuginfo - update to 0.6.6-150600.3.3.1
librav1e0_6-64bit - update to 0.6.6-150600.3.3.1
librav1e0_6-64bit-debuginfo - update to 0.6.6-150600.3.3.1
librav1e0_6-32bit - update to 0.6.6-150600.3.3.1
librav1e0_6-32bit-debuginfo - update to 0.6.6-150600.3.3.1
rav1e - update to 0.6.6-150600.3.3.1
rav1e-debugsource - update to 0.6.6-150600.3.3.1
librav1e0_6-debuginfo - update to 0.6.6-150600.3.3.1
rav1e-devel - update to 0.6.6-150600.3.3.1
librav1e0_6 - update to 0.6.6-150600.3.3.1
gotify-desktop - addressed in versions 1.3.7-5.fc41, 1.3.7-5.fc42, 1.3.7-5.fc43
rustup - addressed in versions 1.26.0~0-150600.10.7.1, 1.28.2~0-150600.10.13.1
rustup-debuginfo - addressed in versions 1.26.0~0-150600.10.7.1, 1.28.2~0-150600.10.13.1
rustup-debugsource - update to 1.28.2~0-150600.10.13.1
rust-git-interactive-rebase-tool - addressed in versions 2.4.1-9.fc41, 2.4.1-9.fc42, 2.4.1-9.fc43
librsvg-2-2-64bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-64bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-64bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-64bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-32bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
rsvg-thumbnailer - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-32bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-32bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-32bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-devel - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
rsvg-convert - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
typelib-1_0-Rsvg-2_0 - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2 - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-debugsource - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg2 - update to 2.57.4-2
librsvg2-devel - update to 2.57.4-2
librsvg2-tools - update to 2.57.4-2
rsvg-convert-debuginfo - update to 2.57.4-150600.3.3.1
mirrorlist-server - addressed in versions 3.0.7-7.fc41, 3.0.7-7.fc42, 3.0.7-7.fc43
atuin - addressed in versions 18.3.0-4.el9, 18.3.0-4.fc41, 18.3.0-4.fc42, 18.3.0-4.fc43
rpm-ostree-help - update to 2022.16-11
rpm-ostree-devel - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-debugsource - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-debuginfo - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-libs - addressed in versions 2024.4-7, 2024.4-8

External References

Related Security Bulletins