Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40403.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-40403
Upstream
Published
2024-05-07T18:15:08Z
Modified
2026-04-01T05:13:36.416807Z
Summary
CVE-2024-34397 affecting package glib for versions less than 2.71.0-7
Details

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

References

Affected packages

Azure Linux:2 / glib

Package

Name
glib
Purl
pkg:rpm/azure-linux/glib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.71.0-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40403.json"