Loading HuntDB...

GHSA-cfjc-m7fv-63xj

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post` options that permit arbitrary scripts with their absolute paths to be passed. These user or attacker-controlled executable scripts or programs could then be executed by Tuned with root privileges that could allow attackers to local privilege escalation.

Related CVEs

Key Information

GHSA ID
GHSA-cfjc-m7fv-63xj
Published
November 26, 2024 6:38 PM
Last Modified
February 3, 2025 9:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.