The `instance_name` parameter of the `instance_create()` method is not sanitized. This string is later on used in logging and in the output of utilities like `tuned-adm get_instances`, or other third party programs that utilize tuned's D-Bus interface to obtain instance names. By adding control characters to the instance name, log spoofing can be achieved. By placing newline characters into the name, seemingly independent and legit log lines can be added to the tuned log. By adding terminal control sequences the terminal emulators of administrators or other users can be influenced
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2024:10381 https://access.redhat.com/errata/RHSA-2024:10381
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:10384 https://access.redhat.com/errata/RHSA-2024:10384
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:11161 https://access.redhat.com/errata/RHSA-2024:11161
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:0195 https://access.redhat.com/errata/RHSA-2025:0195
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:0327 https://access.redhat.com/errata/RHSA-2025:0327
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:0368 https://access.redhat.com/errata/RHSA-2025:0368
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:1785 https://access.redhat.com/errata/RHSA-2025:1785
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:1802 https://access.redhat.com/errata/RHSA-2025:1802