Input validation error in idna - CVE-2024-12224
Published: December 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error within the UTS 46 specification when handling Punycode labels that do not produce any non-ASCII output. A remote attacker can construct a specially crafted hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Fedora
Server Applications Module
Basesystem Module
Development Tools Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
keylime-agent-rust
awatcher
snpguest
snpguest-debuginfo
sccache-debugsource
sccache-debuginfo
sccache
sevctl
sevctl-debuginfo
fido-device-onboard
sevctl-debugsource
rav1e-debuginfo
librav1e0_6-64bit
librav1e0_6-64bit-debuginfo
librav1e0_6-32bit
librav1e0_6-32bit-debuginfo
rav1e
rav1e-debugsource
librav1e0_6-debuginfo
rav1e-devel
librav1e0_6
gotify-desktop
rustup
rustup-debuginfo
rustup-debugsource
rust-git-interactive-rebase-tool
librsvg-2-2-64bit-debuginfo
gdk-pixbuf-loader-rsvg-64bit
librsvg-2-2-64bit
gdk-pixbuf-loader-rsvg-64bit-debuginfo
gdk-pixbuf-loader-rsvg-32bit
rsvg-thumbnailer
librsvg-2-2-32bit-debuginfo
librsvg-2-2-32bit
gdk-pixbuf-loader-rsvg-32bit-debuginfo
librsvg-devel
rsvg-convert
typelib-1_0-Rsvg-2_0
librsvg-2-2
librsvg-2-2-debuginfo
gdk-pixbuf-loader-rsvg-debuginfo
librsvg-debugsource
gdk-pixbuf-loader-rsvg
librsvg2
librsvg2-devel
librsvg2-tools
rsvg-convert-debuginfo
mirrorlist-server
atuin
rpm-ostree-help
rpm-ostree-devel
rpm-ostree-debugsource
rpm-ostree-debuginfo
rpm-ostree
rpm-ostree-libs
How to mitigate CVE-2024-12224
keylime-agent-rust - addressed in versions 0.2.7-5.fc41, 0.2.8-1.fc42
awatcher - addressed in versions 0.3.1-2.fc41, 0.3.1-2.fc42, 0.3.1-2.fc43
snpguest - update to 0.3.2-150600.3.6.1
snpguest-debuginfo - update to 0.3.2-150600.3.6.1
sccache-debugsource - update to 0.4.2~4-150400.3.6.1
sccache-debuginfo - addressed in versions 0.4.2~4-150400.3.6.1, 0.4.2~4-150600.10.3.1
sccache - addressed in versions 0.4.2~4-150400.3.6.1, 0.4.2~4-150600.10.3.1
sevctl - addressed in versions 0.4.3-150600.4.3.1, 0.6.0-150700.3.3.1
sevctl-debuginfo - addressed in versions 0.4.3-150600.4.3.1, 0.6.0-150700.3.3.1
fido-device-onboard - update to 0.5.1-3.fc41
sevctl-debugsource - update to 0.6.0-150700.3.3.1
rav1e-debuginfo - update to 0.6.6-150600.3.3.1
librav1e0_6-64bit - update to 0.6.6-150600.3.3.1
librav1e0_6-64bit-debuginfo - update to 0.6.6-150600.3.3.1
librav1e0_6-32bit - update to 0.6.6-150600.3.3.1
librav1e0_6-32bit-debuginfo - update to 0.6.6-150600.3.3.1
rav1e - update to 0.6.6-150600.3.3.1
rav1e-debugsource - update to 0.6.6-150600.3.3.1
librav1e0_6-debuginfo - update to 0.6.6-150600.3.3.1
rav1e-devel - update to 0.6.6-150600.3.3.1
librav1e0_6 - update to 0.6.6-150600.3.3.1
gotify-desktop - addressed in versions 1.3.7-5.fc41, 1.3.7-5.fc42, 1.3.7-5.fc43
rustup - addressed in versions 1.26.0~0-150600.10.7.1, 1.28.2~0-150600.10.13.1
rustup-debuginfo - addressed in versions 1.26.0~0-150600.10.7.1, 1.28.2~0-150600.10.13.1
rustup-debugsource - update to 1.28.2~0-150600.10.13.1
rust-git-interactive-rebase-tool - addressed in versions 2.4.1-9.fc41, 2.4.1-9.fc42, 2.4.1-9.fc43
librsvg-2-2-64bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-64bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-64bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-64bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-32bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
rsvg-thumbnailer - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-32bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-32bit - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-32bit-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-devel - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
rsvg-convert - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
typelib-1_0-Rsvg-2_0 - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2 - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-2-2-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg-debuginfo - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg-debugsource - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
gdk-pixbuf-loader-rsvg - addressed in versions 2.52.12-150400.3.9.1, 2.57.4-150600.3.3.1
librsvg2 - update to 2.57.4-2
librsvg2-devel - update to 2.57.4-2
librsvg2-tools - update to 2.57.4-2
rsvg-convert-debuginfo - update to 2.57.4-150600.3.3.1
mirrorlist-server - addressed in versions 3.0.7-7.fc41, 3.0.7-7.fc42, 3.0.7-7.fc43
atuin - addressed in versions 18.3.0-4.el9, 18.3.0-4.fc41, 18.3.0-4.fc42, 18.3.0-4.fc43
rpm-ostree-help - update to 2022.16-11
rpm-ostree-devel - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-debugsource - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-debuginfo - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree - addressed in versions 2022.16-11, 2024.4-7, 2024.4-8
rpm-ostree-libs - addressed in versions 2024.4-7, 2024.4-8
External References
Related Security Bulletins
- Spoofing attack in idna crate
- Fedora 43 update for rust-git-interactive-rebase-tool
- Fedora 41 update for rust-git-interactive-rebase-tool
- Fedora 42 update for rust-git-interactive-rebase-tool
- Fedora 41 update for fido-device-onboard
- Fedora 43 update for atuin, awatcher, gotify-desktop, mirrorlist-server
- Fedora 42 update for atuin, awatcher, gotify-desktop, mirrorlist-server
- Fedora 41 update for atuin, awatcher, gotify-desktop, keylime-agent-rust, mirrorlist-server
- Fedora EPEL 9 update for atuin
- Fedora 42 update for keylime-agent-rust
- SUSE update for rav1e
- SUSE update for sccache
- SUSE update for sccache
- SUSE update for rustup
- SUSE update for sevctl
- SUSE update for sevctl
- SUSE update for snpguest
- SUSE update for librsvg
- SUSE update for librsvg
- Anolis OS update for librsvg2
- openEuler 24.03 LTS SP3 update for rpm-ostree
- openEuler 24.03 LTS SP1 update for rpm-ostree
- openEuler 22.03 LTS SP4 update for rpm-ostree
- SUSE update for rustup
- openEuler 24.03 LTS SP4 update for rpm-ostree