The updated packages fix a security vulnerability:
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer
in libdbus, as used in dbus-daemon, leaks file descriptors when a message
exceeds the per-message file descriptor limit. A local attacker with
access to the D-Bus system bus or another system service's private
AF_UNIX socket could use this to make the system service reach its file
descriptor limit, denying service to subsequent D-Bus clients.
(CVE-2020-12049)
- https://bugs.mageia.org/show_bug.cgi?id=26735
- https://www.openwall.com/lists/oss-security/2020/06/04/3
- https://lists.debian.org/debian-lts-announce/2020/06/msg00003.html
- https://www.cve.org/CVERecord?id=CVE-2020-12049
- 7/core/dbus-1.13.8-4.2.mga7
Get the latest Linux and open source security news straight to your inbox.