Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-34397

17
FAUCET Score

CVE-2024-34397 is a medium-severity vulnerability in GNOME GLib versions before 2.78.5, and 2.79.x and 2.80.x before 2.80.1, affecting products like Debian, Fedora, GNOME, and NetApp. An attacker on a shared computer can spoof D-Bus signals, causing GDBus-based clients to misinterpret them as originating from trusted system services, leading to incorrect application behavior. The vulnerability has a CVSS score of 5.2 (MEDIUM) with a physical attack vector, low attack complexity, and potential for high integrity impact and low availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.78.5CPE matchmatch criteria
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
>= 2.79.0, < 2.80.1CPE matchmatch criteria
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.2MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
0.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.76%
Probability of exploitation in next 30 days
EPSS Percentile
51.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0076 is in the 90th percentile among its peer group of 1,532 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (64)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 17571-17084Fixed in: 2.78.6-1
microsoftpatch availablevia msrc
Product: 19898-17086Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: 20466-17086Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: 20365-17086Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: azl3 glib 2.78.6-1 on Azure Linux 3.0Fixed in: 2.78.6-1
microsoftpatch availablevia msrc
Product: azl3 glib 2.78.1-5 on Azure Linux 3.0Fixed in: 2.78.6-1
microsoftpatch availablevia msrc
Product: cbl2 glib 2.71.0-5 on CBL Mariner 2.0Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: cbl2 glib 2.71.0-7 on CBL Mariner 2.0Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: cbl2 glib 2.71.0-6 on CBL Mariner 2.0Fixed in: 2.71.0-7
microsoftpatch availablevia msrc
Product: 17744-17084Fixed in: 2.78.6-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: glib2-0:2.68.4-14.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: mingw-glib2-0:2.78.6-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: glib2-0:2.68.4-7.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.4.7-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.4.7-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.4.7-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.4.3-7
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.4.7-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.4.7-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.4.7-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.4.7-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.4.7-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.4.3-6
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.4.7-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1.4 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.4.7-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-controller-podman-container-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-controller-podman-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.5.3-6
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.5.5-4
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-controller-podman-container-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-controller-podman-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-agent-rhel8:sha256:389b9cbd0f05d3d773edc2c06aa73818307cbb25048bddf4f192a992670b6fb4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-all-in-one-rhel8:sha256:3b00e2fec645e140fa304e5823bcb1d0fcd1ddac7f4cbf6e9a9c0fbeaf29682d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-collector-rhel8:sha256:3dc773cc4a48041bfe69b516db58d2a5060059725351fc1dbcece64778a35b3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-es-index-cleaner-rhel8:sha256:3d98512aaa924e0e1c9f3b5ab6b405cb4f4a3f3b5225aefa54f1b2abfbe3d769
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-es-rollover-rhel8:sha256:1c4617b035c66b6b34e9b19f618f72a19da5fce644d79e24eb262f14c848bc81
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-ingester-rhel8:sha256:03f466002ae14ef14dd0e82e0ab75c5287295f77598eed8aca6d1ac6aaa11928
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-operator-bundle:sha256:be3feca3b19ac609e5ef829887b6d03ca3c504163ed0f9e10b2410cdfb175b72
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-query-rhel8:sha256:3d37f30462f237f5087ef8ac90e39f5cd2cbaf5c143f7cae9d6155eb574726f2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/jaeger-rhel8-operator:sha256:8fb68adefecd8ccb94404399ac6c8038c064c85287f4f980a0855da1cbd0dcb7
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.5.3-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: glib2-0:2.56.4-166.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: glib2-0:2.56.4-8.el8_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: glib2-0:2.56.4-10.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: glib2-0:2.56.4-10.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: glib2-0:2.56.4-158.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: glib2-0:2.56.4-158.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: glib2-0:2.56.4-158.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: glib2-0:2.56.4-162.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: glib2-0:2.56.4-162.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/toolbox:9.4-12.1725906880
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ubi9/toolbox:9.4-12.1725906880
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-glib2

Vendor Advisories (4)

denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
microsoft2024-May/CVE-2024-34397Moderate

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

May 14, 2024
redhatCVE-2024-34397Moderate

glib2: Signal subscription vulnerabilities

May 7, 2024

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
lists.fedoraproject.org / archives/list/[email protected]/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS
lists.fedoraproject.org / archives/list/[email protected]/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH
lists.fedoraproject.org / archives/list/[email protected]/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW
lists.fedoraproject.org / archives/list/[email protected]/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A
gitlab.gnome.org / GNOME/glib/-/issues/3268
ExploitIssue TrackingVendor Advisory
lists.debian.org / debian-lts-announce/2024/05/msg00008.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20240531-0008
Third Party Advisory
openwall.com / lists/oss-security/2024/05/07/5
Mailing List