VDB
RHBA-2024%3A6585
RHBA-2024%3A6585
PUBLISHED
CVSS 3.799999952316284 LOW
A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This issue could lead to the GDBus-based client behaving incorrectly with an application-dependent impact.
Risk Scores
CVSS 3.1
3.799999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | ubi9/toolbox@sha256:c7ea1da5e59a03a7ce0905600fecaadc121c0430cd62cf47cb34a53d7db84420_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9) | ubi9/toolbox@sha256:c7ea1da5e59a03a7ce0905600fecaadc121c0430cd62cf47cb34a53d7db84420_s390x |
| Red Hat | rhel9/toolbox@sha256:18941856982108e0829cd1d35c033c02bdb558300bf43248f31ef035d6ae883e_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | rhel9/toolbox@sha256:18941856982108e0829cd1d35c033c02bdb558300bf43248f31ef035d6ae883e_amd64 |
| Red Hat | ubi9/toolbox@sha256:18941856982108e0829cd1d35c033c02bdb558300bf43248f31ef035d6ae883e_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | ubi9/toolbox@sha256:18941856982108e0829cd1d35c033c02bdb558300bf43248f31ef035d6ae883e_amd64 |
| Red Hat | ubi9/toolbox@sha256:b01977589a75d25f04d94daf5c0f27f18280691b89ddc92441454f2cc4f54341_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9) | ubi9/toolbox@sha256:b01977589a75d25f04d94daf5c0f27f18280691b89ddc92441454f2cc4f54341_ppc64le |
| Red Hat | rhel9/toolbox@sha256:c7ea1da5e59a03a7ce0905600fecaadc121c0430cd62cf47cb34a53d7db84420_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9) | rhel9/toolbox@sha256:c7ea1da5e59a03a7ce0905600fecaadc121c0430cd62cf47cb34a53d7db84420_s390x |
| Red Hat | rhel9/toolbox@sha256:b01977589a75d25f04d94daf5c0f27f18280691b89ddc92441454f2cc4f54341_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9) | rhel9/toolbox@sha256:b01977589a75d25f04d94daf5c0f27f18280691b89ddc92441454f2cc4f54341_ppc64le |
| Red Hat | rhel9/toolbox@sha256:fa82c8a67af71b7f5bdfdbe430d4216fd11d8e710512b5bedfdb47e5f5a04956_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | rhel9/toolbox@sha256:fa82c8a67af71b7f5bdfdbe430d4216fd11d8e710512b5bedfdb47e5f5a04956_arm64 |
| Red Hat | ubi9/toolbox@sha256:fa82c8a67af71b7f5bdfdbe430d4216fd11d8e710512b5bedfdb47e5f5a04956_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | ubi9/toolbox@sha256:fa82c8a67af71b7f5bdfdbe430d4216fd11d8e710512b5bedfdb47e5f5a04956_arm64 |
Timeline
- Sep 11, 2024 CVE Published
- Apr 6, 2026 CVE Updated
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2024:6585 advisory
- https://catalog.redhat.com/software/containers/search advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293942 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_6585.json advisory
- https://access.redhat.com/security/cve/CVE-2024-34397 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2279632 issue
- https://www.cve.org/CVERecord?id=CVE-2024-34397 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34397 advisory
- https://gitlab.gnome.org/GNOME/glib/-/issues/3268 advisory
- https://www.openwall.com/lists/oss-security/2024/05/07/5 advisory
- https://access.redhat.com/security/cve/CVE-2024-37370 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294677 issue
- https://www.cve.org/CVERecord?id=CVE-2024-37370 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-37370 advisory
- https://web.mit.edu/kerberos/www/krb5-1.21/ advisory
- https://access.redhat.com/security/cve/CVE-2024-37371 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294676 issue
- https://www.cve.org/CVERecord?id=CVE-2024-37371 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-37371 advisory
- https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL advisory