Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
It was found that D-Bus, a simple interprocess messaging system, was susceptible to a denial of service vulnerability if a monitor was being run. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3628-1
An update for dbus is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2023:5193-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5193 Issue date: 2023-09-18 CVE Names: CVE-2023-34969 ===================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to takeeffect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 2213166 - CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.6): aarch64: dbus-daemon-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-debugsource-1.12.8-18.el8_6.3.aarch64.rpm dbus-devel-1.12.8-18.el8_6.3.aarch64.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-x11-1.12.8-18.el8_6.3.aarch64.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm ppc64le: dbus-daemon-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-debugsource-1.12.8-18.el8_6.3.ppc64le.rpm dbus-devel-1.12.8-18.el8_6.3.ppc64le.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-x11-1.12.8-18.el8_6.3.ppc64le.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm s390x: dbus-daemon-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-debugsource-1.12.8-18.el8_6.3.s390x.rpm dbus-devel-1.12.8-18.el8_6.3.s390x.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-x11-1.12.8-18.el8_6.3.s390x.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.s390x.rpm x86_64: dbus-daemon-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-debugsource-1.12.8-18.el8_6.3.i686.rpm dbus-debugsource-1.12.8-18.el8_6.3.x86_64.rpm dbus-devel-1.12.8-18.el8_6.3.i686.rpm dbus-devel-1.12.8-18.el8_6.3.x86_64.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-x11-1.12.8-18.el8_6.3.x86_64.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm Red Hat Enterprise Linux BaseOS EUS(v.8.6): Source: dbus-1.12.8-18.el8_6.3.src.rpm aarch64: dbus-1.12.8-18.el8_6.3.aarch64.rpm dbus-daemon-1.12.8-18.el8_6.3.aarch64.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-debugsource-1.12.8-18.el8_6.3.aarch64.rpm dbus-libs-1.12.8-18.el8_6.3.aarch64.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-tools-1.12.8-18.el8_6.3.aarch64.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.aarch64.rpm noarch: dbus-common-1.12.8-18.el8_6.3.noarch.rpm ppc64le: dbus-1.12.8-18.el8_6.3.ppc64le.rpm dbus-daemon-1.12.8-18.el8_6.3.ppc64le.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-debugsource-1.12.8-18.el8_6.3.ppc64le.rpm dbus-libs-1.12.8-18.el8_6.3.ppc64le.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-tools-1.12.8-18.el8_6.3.ppc64le.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.ppc64le.rpm s390x: dbus-1.12.8-18.el8_6.3.s390x.rpm dbus-daemon-1.12.8-18.el8_6.3.s390x.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-debugsource-1.12.8-18.el8_6.3.s390x.rpm dbus-libs-1.12.8-18.el8_6.3.s390x.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-tools-1.12.8-18.el8_6.3.s390x.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.s390x.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.s390x.rpm x86_64: dbus-1.12.8-18.el8_6.3.x86_64.rpm dbus-daemon-1.12.8-18.el8_6.3.x86_64.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-daemon-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-debugsource-1.12.8-18.el8_6.3.i686.rpm dbus-debugsource-1.12.8-18.el8_6.3.x86_64.rpm dbus-libs-1.12.8-18.el8_6.3.i686.rpm dbus-libs-1.12.8-18.el8_6.3.x86_64.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-libs-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-tests-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-tools-1.12.8-18.el8_6.3.x86_64.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-tools-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.i686.rpm dbus-x11-debuginfo-1.12.8-18.el8_6.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCGxOAAoJENzjgjWX9erEVU8QAKLayV3wuBomKQd77UY3lauO 59BvCrHBc2eJTDGnlL5SX3yfoKa7y6Ky83GUnvBtCdjj025crsxHiZahC2MafSOW xkyt7zTGbU3ywPqqhj2g5FJd82irUPzdNDRv3qA6+PF9zn4hR1gOSDTttdpQIvvw F4XC3u6IBu8ffTIrKaLD+Y+eVxqT+/x+IjoH+9ru8eCJVdU5FZKR2MLbDbHBNn9A n8Ax/A8Czc4J83QE+DLFsOIN09bWUQUCX8vlmPpAfeHf2YEG8DCEDNblGVfLw1E0 vxJrn0CVoauovKDzPazsRg9ggE4jNbXdT9oExOYwnQQiG+ZkNyNXvHRewUBFR1ma j6xppqxf0qGSt2xnxncYbm33nSePZqwbLsx0TrH1XROLN1mIpp3qHO9eUytRfurO CKYimW9rpC3h3Kz3LQNlD0D/j+/uvQVWaxlhV9FJ+bei4vC5IrgM3W18Dr4nT05T w3UN+Tzdxu27Q5V5sJf9mFLE2QYqV23LsnghM6AWYbd6ASNg1Qp7Znx0JjdJGYN3 T2IYRxlT1G6xs9NzWlsFbnwKXgJv9uZ3JpBlhKcABTCSoK5Sfrv8+K+DoR+Ky0mP n8PIGazj03N2L/Lk1wJ5K9QIxq9DrhToLW2wgpsC7rkVR99FkNbYGHVnFVR6WDzS L63te9A6Nqk0gq6BINoD =mQ7E -----END PGP SIGNATURE----- -- RHSA-announce mailing list
DBus could be made to crash if it received a specially crafted request.. ========================================================================== Ubuntu Security Notice USN-6372-1 September 14, 2023 dbus vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: DBus could be made to crash if it received a specially crafted request. Software Description: - dbus: simple interprocess messaging system Details: It was discovered that DBus incorrectly handled certain invalid messages. A local attacker could possibly use this issue to cause DBus to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): dbus 1.10.6-1ubuntu3.6+esm3 libdbus-1-3 1.10.6-1ubuntu3.6+esm3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6372-1 CVE-2023-34969 . Ubuntu Security Notice USN-6372-1 resolves a DBus crash vulnerability caused by specially crafted messages, offers guidance for remediation.. Ubuntu Security Notice, DBus Crash, Denial Of Service, Update Instructions. . Severity: Important. LinuxSecurity.com Team
Moderate: dbus security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4569", "synopsis": "Moderate: dbus security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for dbus.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.\n\nSecurity Fix(es):\n\n* dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2213166", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2213166", "description": ""}], "cves": [{"name": "CVE-2023-34969", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-34969", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-08-24T04:21:33.856417Z", "rpms": {"Rocky Linux 9": {"nvras": ["dbus-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-1:1.12.20-7.el9_2.1.src.rpm", "dbus-common-1:1.12.20-7.el9_2.1.noarch.rpm", "dbus-daemon-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-daemon-debuginfo-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-debuginfo-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-debugsource-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-devel-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-libs-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-libs-debuginfo-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-tools-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-tools-debuginfo-1:1.12.20-7.el9_2.1.aarch64.rpm","dbus-x11-1:1.12.20-7.el9_2.1.aarch64.rpm", "dbus-x11-debuginfo-1:1.12.20-7.el9_2.1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security patch has been released for dbus in Rocky Linux 9, targeting moderate risk vulnerabilities and reinforcing overall system integrity.. Rocky Linux Security, System Messaging Fix, Linux Application Update. . LinuxSecurity.com Team
Moderate: dbus security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:4498", "synopsis": "Moderate: dbus security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for dbus.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.\n\nSecurity Fix(es):\n\n* dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2213166", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2213166", "description": ""}], "cves": [{"name": "CVE-2023-34969", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-34969", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.2", "cwe": "CWE-617"}], "references": [], "publishedAt": "2023-08-24T04:20:17.019312Z", "rpms": {"Rocky Linux 8": {"nvras": ["dbus-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-1:1.12.8-24.el8_8.1.src.rpm", "dbus-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-common-1:1.12.8-24.el8_8.1.noarch.rpm", "dbus-daemon-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-daemon-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-daemon-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-daemon-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm","dbus-debugsource-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-debugsource-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-debugsource-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-devel-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-libs-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.i686.rpm", "dbus-libs-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-tools-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-tools-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-tools-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-tools-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-x11-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-x11-1:1.12.8-24.el8_8.1.x86_64.rpm", "dbus-x11-debuginfo-1:1.12.8-24.el8_8.1.aarch64.rpm", "dbus-x11-debuginfo-1:1.12.8-24.el8_8.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The recent update for Rocky Linux addressing dbus has fixed a notable security vulnerability stemming from an assertion failure. It is advisable to upgrade for enhanced system stability.. Rocky Linux Security, Dbus Updates, Assertion Issue, System Services. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4498 https://linux.oracle.com/errata/ELSA-2023-4498.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: dbus-1.12.8-24.0.1.el8_8.1.x86_64.rpm dbus-common-1.12.8-24.0.1.el8_8.1.noarch.rpm dbus-daemon-1.12.8-24.0.1.el8_8.1.x86_64.rpm dbus-devel-1.12.8-24.0.1.el8_8.1.i686.rpm dbus-devel-1.12.8-24.0.1.el8_8.1.x86_64.rpm dbus-libs-1.12.8-24.0.1.el8_8.1.i686.rpm dbus-libs-1.12.8-24.0.1.el8_8.1.x86_64.rpm dbus-tools-1.12.8-24.0.1.el8_8.1.x86_64.rpm dbus-x11-1.12.8-24.0.1.el8_8.1.x86_64.rpm aarch64: dbus-1.12.8-24.0.1.el8_8.1.aarch64.rpm dbus-common-1.12.8-24.0.1.el8_8.1.noarch.rpm dbus-daemon-1.12.8-24.0.1.el8_8.1.aarch64.rpm dbus-devel-1.12.8-24.0.1.el8_8.1.aarch64.rpm dbus-libs-1.12.8-24.0.1.el8_8.1.aarch64.rpm dbus-tools-1.12.8-24.0.1.el8_8.1.aarch64.rpm dbus-x11-1.12.8-24.0.1.el8_8.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//dbus-1.12.8-24.0.1.el8_8.1.src.rpm Related CVEs: CVE-2023-34969 Description of changes: [1:1.12.8-24.0.1.1] - Fix CVE-2023-34969 (#2213166) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4569 https://linux.oracle.com/errata/ELSA-2023-4569.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: dbus-1.12.20-7.0.1.el9_2.1.x86_64.rpm dbus-common-1.12.20-7.0.1.el9_2.1.noarch.rpm dbus-daemon-1.12.20-7.0.1.el9_2.1.x86_64.rpm dbus-devel-1.12.20-7.0.1.el9_2.1.i686.rpm dbus-devel-1.12.20-7.0.1.el9_2.1.x86_64.rpm dbus-libs-1.12.20-7.0.1.el9_2.1.i686.rpm dbus-libs-1.12.20-7.0.1.el9_2.1.x86_64.rpm dbus-tools-1.12.20-7.0.1.el9_2.1.x86_64.rpm dbus-x11-1.12.20-7.0.1.el9_2.1.x86_64.rpm aarch64: dbus-1.12.20-7.0.1.el9_2.1.aarch64.rpm dbus-common-1.12.20-7.0.1.el9_2.1.noarch.rpm dbus-daemon-1.12.20-7.0.1.el9_2.1.aarch64.rpm dbus-devel-1.12.20-7.0.1.el9_2.1.aarch64.rpm dbus-libs-1.12.20-7.0.1.el9_2.1.aarch64.rpm dbus-tools-1.12.20-7.0.1.el9_2.1.aarch64.rpm dbus-x11-1.12.20-7.0.1.el9_2.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//dbus-1.12.20-7.0.1.el9_2.1.src.rpm Related CVEs: CVE-2023-34969 Description of changes: [1:1.12.20-7.0.1.1] - Fix CVE-2023-34969 (#2213402) [1.12.20-7.0.1] - fix netlink poll: error 4 (Zhenzhong Duan) [1:1.12.20-7] - Fix CVE-2022-42010 (#2133647) - Fix CVE-2022-42011 (#2133641) - Fix CVE-2022-42012 (#2133635) [1:1.12.20-6] - Override upstream sysusers.d confguration (#2118226) [1:1.12.20-5] - Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688 _______________________________________________ El-errata mailing list
An update for dbus is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2023:4569-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4569 Issue date: 2023-08-08 CVE Names: CVE-2023-34969 ===================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For theupdate to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 2213166 - CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered 6. Package List: Red Hat Enterprise Linux AppStream (v.9): aarch64: dbus-daemon-1.12.20-7.el9_2.1.aarch64.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-debugsource-1.12.20-7.el9_2.1.aarch64.rpm dbus-devel-1.12.20-7.el9_2.1.aarch64.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-x11-1.12.20-7.el9_2.1.aarch64.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm ppc64le: dbus-daemon-1.12.20-7.el9_2.1.ppc64le.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-debugsource-1.12.20-7.el9_2.1.ppc64le.rpm dbus-devel-1.12.20-7.el9_2.1.ppc64le.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-x11-1.12.20-7.el9_2.1.ppc64le.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm s390x: dbus-daemon-1.12.20-7.el9_2.1.s390x.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-debugsource-1.12.20-7.el9_2.1.s390x.rpm dbus-devel-1.12.20-7.el9_2.1.s390x.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-x11-1.12.20-7.el9_2.1.s390x.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.s390x.rpm x86_64: dbus-daemon-1.12.20-7.el9_2.1.x86_64.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-debugsource-1.12.20-7.el9_2.1.i686.rpm dbus-debugsource-1.12.20-7.el9_2.1.x86_64.rpm dbus-devel-1.12.20-7.el9_2.1.i686.rpm dbus-devel-1.12.20-7.el9_2.1.x86_64.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-x11-1.12.20-7.el9_2.1.x86_64.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.9): Source: dbus-1.12.20-7.el9_2.1.src.rpm aarch64: dbus-1.12.20-7.el9_2.1.aarch64.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-debugsource-1.12.20-7.el9_2.1.aarch64.rpm dbus-libs-1.12.20-7.el9_2.1.aarch64.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-tools-1.12.20-7.el9_2.1.aarch64.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.aarch64.rpm noarch: dbus-common-1.12.20-7.el9_2.1.noarch.rpm ppc64le: dbus-1.12.20-7.el9_2.1.ppc64le.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-debugsource-1.12.20-7.el9_2.1.ppc64le.rpm dbus-libs-1.12.20-7.el9_2.1.ppc64le.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-tools-1.12.20-7.el9_2.1.ppc64le.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.ppc64le.rpm s390x: dbus-1.12.20-7.el9_2.1.s390x.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-debugsource-1.12.20-7.el9_2.1.s390x.rpm dbus-libs-1.12.20-7.el9_2.1.s390x.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-tools-1.12.20-7.el9_2.1.s390x.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.s390x.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.s390x.rpm x86_64: dbus-1.12.20-7.el9_2.1.x86_64.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-daemon-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-debugsource-1.12.20-7.el9_2.1.i686.rpm dbus-debugsource-1.12.20-7.el9_2.1.x86_64.rpm dbus-libs-1.12.20-7.el9_2.1.i686.rpm dbus-libs-1.12.20-7.el9_2.1.x86_64.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-libs-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-tests-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-tools-1.12.20-7.el9_2.1.x86_64.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-tools-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.i686.rpm dbus-x11-debuginfo-1.12.20-7.el9_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk0qOIAAoJENzjgjWX9erEqicP/Aghm295i1cVKdG1tSNj7isd i9i2+4kzWpNH4jMEwJHGE9Zf5sbkuEo2v+M32CSKXo+ahIt/ZoXV7VNXiUWPAdWF 80Y3kW3YKLXg1a0MqZurVmBz4bj+Pf9bHK+PoRqyr0R+PmDsNvURMyGwAdmkP5e5 qCEZKC3wD0m6cEQR6+CFmw1umc7klvCrzDMDfkBTkT6LHd0L3kx/CdKAhmaD90Wp YyetYsNWX37iBXUYcjK0VNQqiwz3RMMpemZMXMo4v/C4CVVR6cABxnR2YpONy4KW uD2mx84M3gcvSuameqISkw7+QizY/lquA87zPXu/IwskraWzpfpDtQV0SdeSRbni DVsEC7i0OX/7f9uX3bYQXt6evCN5TUzpAFLnJmauPFBuq5+5l3PZXHGTecYJ9ANV JS2RYkCeTKAojeC/QAedKB6nDsg4NYlyK/9DCcbU5ERvAPOT0rsdxMTlcyXkI4TB ATz7zcKJWj1EJvaZZk00+jwwp07g7e0hvhyJqsJazfHaD9djOG0tNoYFG3gQNSCk /ifzbPaHepW6TOayqLOEFN+9A6XuJNDAgF6AOY77qCzSIlJa3wTDWaSUJiQsLhDu deDOjWl/Qjtm+AbNhmuKmnzeOPvnl78xwMazmx7P7GR29s7gfApt6Jebyfbo5YnI SlSOCtfoIWe4qbvVZcp8 =8vma -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.