Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: 2020-0262 Critical: Dbus File Descriptor Leak Advisory

mageia
Calendar Grey June 15, 2020
Dist Mageia Esm H88
Recent updates to the dbus packages have fixed a file descriptor leak issue that could impact service reliability. For further details, see MGASA-2020-0262
The updated packages fix a security vulnerability: An issue was discovered in dbus >= 1.3.0 before 1.12.18

Summary

The updated packages fix a security vulnerability: An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients. (CVE-2020-12049)

References

- https://bugs.mageia.org/show_bug.cgi?id=26735

- https://www.openwall.com/lists/oss-security/2020/06/04/3

- https://lists.debian.org/debian-lts-announce/2020/06/msg00003.html

- https://www.cve.org/CVERecord?id=CVE-2020-12049

Resolution

SRPMS

- 7/core/dbus-1.13.8-4.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0262.html
Type: security
CVE: CVE-2020-12049

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here