CVE-2024-52336

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post` options that permit arbitrary scripts with their absolute paths to be passed. These user or attacker-controlled executable scripts or programs could then be executed by Tuned with root privileges that could allow attackers to local privilege escalation.
Configurations

No configuration.

History

03 Feb 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:0879 -
  • () https://access.redhat.com/errata/RHSA-2025:0880 -

05 Dec 2024, 14:15

Type Values Removed Values Added
CWE CWE-269

02 Dec 2024, 14:15

Type Values Removed Values Added
References
  • () https://www.openwall.com/lists/oss-security/2024/11/28/1 -

29 Nov 2024, 05:15

Type Values Removed Values Added
References
  • () https://security.opensuse.org/2024/11/26/tuned-instance-create.html -
  • () https://www.openwall.com/lists/oss-security/2024/11/28/2 -

26 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-26 16:15

Updated : 2025-02-03 20:15


NVD link : CVE-2024-52336

Mitre link : CVE-2024-52336

CVE.ORG link : CVE-2024-52336


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management