RHSA-2024:10384HighCVSS 7.8
Red Hat Security Advisory: tuned security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-52336 — tuned: script_pre and script_post options allow to pass arbitrary scripts executed by root
CVE-2024-52337 — tuned: improper sanitization of instance_name parameter of the instance_create() method
🎯 Affected products24
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux Real Time (v. 9)
- Red Hat Enterprise Linux Real Time for NFV (v. 9)
- Red Hat Enterprise Linux for SAP (v. 9)
- Red Hat Enterprise Linux for SAP HANA (v. 9)
- tuned-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tuned-0:2.24.0-2.el9_5.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tuned-gtk-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-ppd-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-profiles-atomic-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-profiles-cpu-partitioning-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tuned-profiles-mssql-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-profiles-nfv-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
- tuned-profiles-nfv-guest-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
- tuned-profiles-nfv-host-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
- tuned-profiles-oracle-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-profiles-postgresql-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-profiles-realtime-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux Real Time (v. 9)
- tuned-profiles-realtime-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux Real Time for NFV (v. 9)
- tuned-profiles-sap-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux for SAP (v. 9)
- tuned-profiles-sap-hana-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux for SAP HANA (v. 9)
- tuned-profiles-spectrumscale-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- tuned-utils-0:2.24.0-2.el9_5.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:10384
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324540
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324541
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10384.json