A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass a controlled sequence of characters; newlines can be inserted into the log. Instead of the 'evil' the attacker could mimic a valid TuneD log line and trick the administrator. The quotes '' are usually used in TuneD logs citing raw user input, so there will always be the ' character ending the spoofed input, and the administrator can easily overlook this. This logged string is later used in logging and in the output of utilities, for example, `tuned-adm get_instances` or other third-party programs that use Tuned's D-Bus interface for such operations.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tuned-profiles-compatUpgrade tuned-profiles-atomicUpgrade tuned-profiles-oracleUpgrade tuned-gtkUpgrade tuned-profiles-postgresqlUpgrade tuned-ppdUpgrade tuned-utilsUpgrade tuned-utils-systemtapUpgrade tunedUpgrade tuned-profiles-spectrumscaleUpgrade tuned-profiles-mssqlUpgrade tuned-profiles-realtimeUpgrade tuned-profiles-cpu-partitioning | Dec 4, 2024 | Nov 26, 2024 |
| Debian | — | Upgrade tuned | Jul 27, 2026 | Jul 27, 2026 |
| Oracle_linux | — | Upgrade tuned-profiles-compatUpgrade tuned-ppdUpgrade tuned-utilsUpgrade tuned-profiles-atomicUpgrade tunedUpgrade tuned-profiles-ociUpgrade tuned-profiles-oracleUpgrade tuned-profiles-spectrumscaleUpgrade tuned-profiles-cpu-partitioningUpgrade tuned-utils-systemtapUpgrade tuned-gtkUpgrade tuned-profiles-mssqlUpgrade tuned-profiles-oci-recommendUpgrade tuned-profiles-postgresql | Dec 3, 2024 | Nov 26, 2024 |
| Redhat_linux | — | Upgrade tuned-profiles-sap-hanaUpgrade tunedUpgrade tuned-utilsUpgrade tuned-profiles-atomicUpgrade tuned-profiles-compatUpgrade tuned-profiles-realtimeUpgrade tuned-gtkUpgrade tuned-profiles-cpu-partitioningUpgrade tuned-profiles-nfv-guestUpgrade tuned-ppdUpgrade tuned-profiles-nfv-hostUpgrade tuned-profiles-spectrumscaleUpgrade tuned-profiles-oracleUpgrade tuned-profiles-mssqlUpgrade tuned-profiles-nfvUpgrade tuned-profiles-sapNo solution existsUpgrade tuned-utils-systemtapUpgrade tuned-profiles-postgresql | Jan 10, 2025 | Nov 26, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub