An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system services private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dbus | Freedesktop | 1.3.0 (including) | 1.12.18 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | dbus-1:1.10.24-14.el7_8 | * |
Red Hat Enterprise Linux 8 | RedHat | dbus-1:1.12.8-10.el8_2 | * |
Red Hat Enterprise Linux 8 | RedHat | dbus-1:1.12.8-10.el8_2 | * |
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | RedHat | dbus-1:1.12.8-8.el8_0 | * |
Red Hat Enterprise Linux 8.1 Extended Update Support | RedHat | dbus-1:1.12.8-10.el8_1 | * |
Dbus | Ubuntu | bionic | * |
Dbus | Ubuntu | devel | * |
Dbus | Ubuntu | eoan | * |
Dbus | Ubuntu | focal | * |
Dbus | Ubuntu | trusty | * |
Dbus | Ubuntu | trusty/esm | * |
Dbus | Ubuntu | upstream | * |
Dbus | Ubuntu | xenial | * |