CVE-2024-34397
NixOS vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2024-34397) was discovered in GNOME GLib before version 2.78.5, and versions 2.79.x and 2.80.x before 2.80.1. The vulnerability was disclosed on May 7, 2024, affecting GDBus-based client systems that subscribe to signals from trusted system services like NetworkManager on shared computers (NVD, OSS Security).

Technical details

The vulnerability exists in the GDBus signal subscription handling mechanism. When a GDBus-based client subscribes to signals from a trusted system service, the system fails to properly validate the signal source. This issue has likely existed since GDBus was first introduced in GLib 2.26, though it has been specifically verified in GLib versions 2.66, 2.74, 2.78 (<2.78.5) and 2.80 (<2.80.1). The vulnerability has been assigned a CVSS v3.1 base score of 5.2 (Medium) with vector AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L (OSS Security, NVD).

Impact

If exploited, this vulnerability allows other users on the same computer to send spoofed D-Bus signals that the GDBus-based client will incorrectly interpret as having been sent by the trusted system service. This can cause the GDBus-based client to behave incorrectly, with impacts varying depending on the specific application (NVD, Debian LTS).

Mitigation and workarounds

The vulnerability has been fixed in GLib versions 2.78.5 and 2.80.1. Additionally, a related fix in gnome-shell is required to prevent regression in screen recording support in gnome-shell 3.38 and newer. Distributions are advised to implement both fixes simultaneously to maintain functionality (OSS Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-32322HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26439HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26431HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-22415MEDIUM4
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26419LOW3.3
  • NixOSNixOS
  • android
NoNoSep 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management