An update for dbus is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2023:4498-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4498 Issue date: 2023-08-07 CVE Names: CVE-2023-34969 ===================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered (CVE-2023-34969) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For theupdate to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 2213166 - CVE-2023-34969 dbus: dbus-daemon: assertion failure when a monitor is active and a message from the driver cannot be delivered 6. Package List: Red Hat Enterprise Linux AppStream (v.8): aarch64: dbus-daemon-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-debugsource-1.12.8-24.el8_8.1.aarch64.rpm dbus-devel-1.12.8-24.el8_8.1.aarch64.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-x11-1.12.8-24.el8_8.1.aarch64.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm ppc64le: dbus-daemon-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-debugsource-1.12.8-24.el8_8.1.ppc64le.rpm dbus-devel-1.12.8-24.el8_8.1.ppc64le.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-x11-1.12.8-24.el8_8.1.ppc64le.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm s390x: dbus-daemon-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-debugsource-1.12.8-24.el8_8.1.s390x.rpm dbus-devel-1.12.8-24.el8_8.1.s390x.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-x11-1.12.8-24.el8_8.1.s390x.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.s390x.rpm x86_64: dbus-daemon-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-debugsource-1.12.8-24.el8_8.1.i686.rpm dbus-debugsource-1.12.8-24.el8_8.1.x86_64.rpm dbus-devel-1.12.8-24.el8_8.1.i686.rpm dbus-devel-1.12.8-24.el8_8.1.x86_64.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-x11-1.12.8-24.el8_8.1.x86_64.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.8): Source: dbus-1.12.8-24.el8_8.1.src.rpm aarch64: dbus-1.12.8-24.el8_8.1.aarch64.rpm dbus-daemon-1.12.8-24.el8_8.1.aarch64.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-debugsource-1.12.8-24.el8_8.1.aarch64.rpm dbus-libs-1.12.8-24.el8_8.1.aarch64.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-tools-1.12.8-24.el8_8.1.aarch64.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.aarch64.rpm noarch: dbus-common-1.12.8-24.el8_8.1.noarch.rpm ppc64le: dbus-1.12.8-24.el8_8.1.ppc64le.rpm dbus-daemon-1.12.8-24.el8_8.1.ppc64le.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-debugsource-1.12.8-24.el8_8.1.ppc64le.rpm dbus-libs-1.12.8-24.el8_8.1.ppc64le.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-tools-1.12.8-24.el8_8.1.ppc64le.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.ppc64le.rpm s390x: dbus-1.12.8-24.el8_8.1.s390x.rpm dbus-daemon-1.12.8-24.el8_8.1.s390x.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-debugsource-1.12.8-24.el8_8.1.s390x.rpm dbus-libs-1.12.8-24.el8_8.1.s390x.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-tools-1.12.8-24.el8_8.1.s390x.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.s390x.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.s390x.rpm x86_64: dbus-1.12.8-24.el8_8.1.x86_64.rpm dbus-daemon-1.12.8-24.el8_8.1.x86_64.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-daemon-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-debugsource-1.12.8-24.el8_8.1.i686.rpm dbus-debugsource-1.12.8-24.el8_8.1.x86_64.rpm dbus-libs-1.12.8-24.el8_8.1.i686.rpm dbus-libs-1.12.8-24.el8_8.1.x86_64.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-libs-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-tests-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-tools-1.12.8-24.el8_8.1.x86_64.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-tools-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.i686.rpm dbus-x11-debuginfo-1.12.8-24.el8_8.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk0P29AAoJENzjgjWX9erEIpIP/iA+jp4RpqfkakYFyKwh/Ri+ /uBcu4iMdJtLK/gdPGh3EAImZ5yyyunfsd0vFg31QDkO/rTbREaHMJAF/Z/Yk/bH gY0lm+3ooT/uPV0SS6b3lHMw+JdUNrFXOW7WD4UTGylTrt4zGadPx3buDkFNF2K/ t8ToRWw2gcqP04NZvYCdyAGj+29asS//LMgHkq8V4fxvGDlW/p2rTIQXJg4O0V45 s5c46F3rwpfcx8OKmDSO+EogQosT5dG92YYKTvWRpfujYz2hQMW7WUASajB3eXBZ sNRMNI/g9wjPNRRPvn2oMNGkcc+sjAHkkI8AS37cafC2HtTIsvlicnE9TPafCnYx i7TvKqy3/oJ2bx11X99D77tVwlRvXfaKVhCi+qyXA/8SXI6H81OYfjqzL27Gff4Q /kJmoIob2wWoFlV4zElEBT5ByTI/JZ/T7d6p2cNrIXtajuPWkmF2+Ic3j3XMiQkw WhjMOuf/fCm3kDuZFDyO5aen6DqEMgvL8GzVN4F1WNtkkG8kqGr+L0MUu2yDvB1L T+vrTPItN8NqRjImEJwn/rtJRb4sepkTR1hdr0XukaJJiyhdyTOGkOkYvXRCcrqD NG0AD3gcGKRs8Pg+J2Bbzy4RVnsFlX4+z8Dtomr00Yd8j6H7Ko58Xqgtzuze4z9Z 7mrHj3Q/YVchFCMQTB0l =Je9q -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for dbus is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2023:0096-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0096 Issue date: 2023-01-12 CVE Names: CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 ==================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010) * dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011) * dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and otherrelated information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 2133616 - CVE-2022-42010 dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets 2133617 - CVE-2022-42011 dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type 2133618 - CVE-2022-42012 dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly 6. Package List: Red Hat Enterprise Linux AppStream (v.8): aarch64: dbus-daemon-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-debugsource-1.12.8-23.el8_7.1.aarch64.rpm dbus-devel-1.12.8-23.el8_7.1.aarch64.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-x11-1.12.8-23.el8_7.1.aarch64.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm ppc64le: dbus-daemon-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-debugsource-1.12.8-23.el8_7.1.ppc64le.rpm dbus-devel-1.12.8-23.el8_7.1.ppc64le.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-x11-1.12.8-23.el8_7.1.ppc64le.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm s390x: dbus-daemon-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-debugsource-1.12.8-23.el8_7.1.s390x.rpm dbus-devel-1.12.8-23.el8_7.1.s390x.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-x11-1.12.8-23.el8_7.1.s390x.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.s390x.rpm x86_64: dbus-daemon-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-debugsource-1.12.8-23.el8_7.1.i686.rpm dbus-debugsource-1.12.8-23.el8_7.1.x86_64.rpm dbus-devel-1.12.8-23.el8_7.1.i686.rpm dbus-devel-1.12.8-23.el8_7.1.x86_64.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-x11-1.12.8-23.el8_7.1.x86_64.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.8): Source: dbus-1.12.8-23.el8_7.1.src.rpm aarch64: dbus-1.12.8-23.el8_7.1.aarch64.rpm dbus-daemon-1.12.8-23.el8_7.1.aarch64.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-debugsource-1.12.8-23.el8_7.1.aarch64.rpm dbus-libs-1.12.8-23.el8_7.1.aarch64.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-tools-1.12.8-23.el8_7.1.aarch64.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.aarch64.rpm noarch: dbus-common-1.12.8-23.el8_7.1.noarch.rpm ppc64le: dbus-1.12.8-23.el8_7.1.ppc64le.rpm dbus-daemon-1.12.8-23.el8_7.1.ppc64le.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-debugsource-1.12.8-23.el8_7.1.ppc64le.rpm dbus-libs-1.12.8-23.el8_7.1.ppc64le.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-tools-1.12.8-23.el8_7.1.ppc64le.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.ppc64le.rpm s390x: dbus-1.12.8-23.el8_7.1.s390x.rpm dbus-daemon-1.12.8-23.el8_7.1.s390x.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-debugsource-1.12.8-23.el8_7.1.s390x.rpm dbus-libs-1.12.8-23.el8_7.1.s390x.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-tools-1.12.8-23.el8_7.1.s390x.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.s390x.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.s390x.rpm x86_64: dbus-1.12.8-23.el8_7.1.x86_64.rpm dbus-daemon-1.12.8-23.el8_7.1.x86_64.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-daemon-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-debugsource-1.12.8-23.el8_7.1.i686.rpm dbus-debugsource-1.12.8-23.el8_7.1.x86_64.rpm dbus-libs-1.12.8-23.el8_7.1.i686.rpm dbus-libs-1.12.8-23.el8_7.1.x86_64.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-libs-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-tests-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-tools-1.12.8-23.el8_7.1.x86_64.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-tools-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.i686.rpm dbus-x11-debuginfo-1.12.8-23.el8_7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-42010 https://access.redhat.com/security/cve/CVE-2022-42011 https://access.redhat.com/security/cve/CVE-2022-42012 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY7/i3dzjgjWX9erEAQjvgQ//amTIwzga07Gm+tHjXgqVgNbqz2eJYJFV uyFUL7QnCdlP9NnYTe9hXKgMnpJgc+vfl1BQCbeH7Np1X77tIXO9oWrCJtAH6mNp aaIEOBrq3hGiNbgjG2SWnwVSPtnBn4RQZSiUhZn6CdlSCEdEsfBHppUrUCO6gFrE n+7/abMkcmsPSFtIJNFN17/92OaLChPLm7PdzJ/EmbhmTznG8mevz0DspbDyPAE/ R/Z5h4QXyvad/ZDVg/3euFC/ny/6FaXJW3PoUReFQ3luCA8rgpoNmh1m/glninC9 KMrfn/o87iaTI71k70+M7OwkHw3xo6NmWsaQ2HEq/j1tzjsRD6sjx0eYoowbWL2A pVY5mxrNXcDegtOZ/Aa/X44Hd9KWRZ9Fse+ye85yeakaTRjFaijYe6URrFs/tDaO R3XVtlKqXyS9yStF6jZLaBdZhGBAxAEM/IOKV38dSIat0dzQ2SQr5+GaCtVhaN+t iQG3CF67hYkDIylX0F7fZVrbtFOQXbsvkCcL7qwRCXAS3aAYRHLZpPwDex26uw4Q aGTs3eBYhVQ1VAPjJdkVAROqBa31T9RBn/UuUzvadbY6J0gWeNYB45OvEHpJ2Zkg eW1YYrrU/si+mSwZsXOYniNTfY0AVaCgRndyIAl0NL1jRFvi6MU66V2LW5Zcqwq6 Cu/RYePhzYs=iJ9Z -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for dbus is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: dbus security update Advisory ID: RHSA-2020:2894-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2894 Issue date: 2020-07-13 CVE Names: CVE-2020-12049 ==================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. Security Fix(es): * dbus: denial of service via file descriptor leak (CVE-2020-12049) For more details about the security issue(s), including the impact, aCVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 1849041 - CVE-2020-12049 dbus: denial of service via file descriptor leak 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: dbus-1.10.24-14.el7_8.src.rpm x86_64: dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: dbus-doc-1.10.24-14.el7_8.noarch.rpm x86_64: dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24-14.el7_8.x86_64.rpm dbus-tests-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: dbus-1.10.24-14.el7_8.src.rpm x86_64: dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: dbus-doc-1.10.24-14.el7_8.noarch.rpm x86_64: dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24-14.el7_8.x86_64.rpm dbus-tests-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: dbus-1.10.24-14.el7_8.src.rpm ppc64: dbus-1.10.24-14.el7_8.ppc64.rpm dbus-debuginfo-1.10.24-14.el7_8.ppc.rpm dbus-debuginfo-1.10.24-14.el7_8.ppc64.rpm dbus-devel-1.10.24-14.el7_8.ppc.rpm dbus-devel-1.10.24-14.el7_8.ppc64.rpm dbus-libs-1.10.24-14.el7_8.ppc.rpm dbus-libs-1.10.24-14.el7_8.ppc64.rpm dbus-x11-1.10.24-14.el7_8.ppc64.rpm ppc64le: dbus-1.10.24-14.el7_8.ppc64le.rpm dbus-debuginfo-1.10.24-14.el7_8.ppc64le.rpm dbus-devel-1.10.24-14.el7_8.ppc64le.rpm dbus-libs-1.10.24-14.el7_8.ppc64le.rpm dbus-x11-1.10.24-14.el7_8.ppc64le.rpm s390x: dbus-1.10.24-14.el7_8.s390x.rpm dbus-debuginfo-1.10.24-14.el7_8.s390.rpm dbus-debuginfo-1.10.24-14.el7_8.s390x.rpm dbus-devel-1.10.24-14.el7_8.s390.rpm dbus-devel-1.10.24-14.el7_8.s390x.rpm dbus-libs-1.10.24-14.el7_8.s390.rpm dbus-libs-1.10.24-14.el7_8.s390x.rpm dbus-x11-1.10.24-14.el7_8.s390x.rpm x86_64: dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: dbus-doc-1.10.24-14.el7_8.noarch.rpm ppc64: dbus-debuginfo-1.10.24-14.el7_8.ppc64.rpm dbus-tests-1.10.24-14.el7_8.ppc64.rpm ppc64le: dbus-debuginfo-1.10.24-14.el7_8.ppc64le.rpm dbus-tests-1.10.24-14.el7_8.ppc64le.rpm s390x: dbus-debuginfo-1.10.24-14.el7_8.s390x.rpm dbus-tests-1.10.24-14.el7_8.s390x.rpm x86_64: dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-tests-1.10.24-14.el7_8.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: dbus-1.10.24-14.el7_8.src.rpm x86_64: dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm Red Hat EnterpriseLinux Workstation Optional (v. 7): noarch: dbus-doc-1.10.24-14.el7_8.noarch.rpm x86_64: dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-tests-1.10.24-14.el7_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12049 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXwxEJtzjgjWX9erEAQhuXhAAjAHRc/ggHB801vkA+U2uPEFdIO/oDTNX lq0XW72FUdjzrE0sNEAZbkpY6NxbA76HFDYHonP9o3DrUN6qd9I4xZgcqoCvZmIw ibDKmS+wAC9bY/7kw74FAQgvabJOq5Aq5TtQU0BKLq7Fx1q3d48O97JvusDbmxFP vezwKSJ+EPH0R/CzJHSm9KJsg+ukk+k+QfI0IOcFzCwVxG/9M91Ck9cvj6rOY6Du HRYTJ9POxD86eyN58V8PbzvqWW7Qq890KBcQ1T8t2hUFAuPX5koB1dbFMK6/C4bn wKL0shJUEpinZJZcQHinjqMsak2YfEotiyDpPGOk316y+1deFXhntAIEr2kwTgF7 57RaQpnmTYlTBdwDwY7vQ6IW6vRb+8LBEt8MwHCnA3+4hUVJNro+2Jz6iU7ZqGqC 4Q1pBuYs50RXp3aluU1LSMhNCnXJYRxgC/8Pq8FIYFcacGXqCuYQne9SjeI/+cil Fg25wepzdVWHoC6xLuamqXJLN6OBAsygW2ukjO2Bj91YS3oca72/mByNwwHXaU25 uYAgCkXq1V9VsD5KrR431UT63Wcd8IvQAHNDCaxsCVYQa4JT5bXeKpI+xOdejJVb HsPE33Tqijsfh0IWLwRIVZQ8U0dJlNVQeXIc1K1bKwV4xVBtkhKOxtgz+YATwN1T jbEVBIlP1Tc=IhCt -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated dbus packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2011:1132-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1132.html Issue date: 2011-08-09 CVE Names: CVE-2011-2200 ==================================================================== 1. Summary: Updated dbus packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - noarch Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch 3. Description: D-Bus is a system for sending messages between applications. It is used for the system-wide message bus service and as a per-user-login-session messaging facility. A denial of service flaw was found in the way the D-Bus library handled endianness conversion when receiving messages. A local usercould use this flaw to send a specially-crafted message to dbus-daemon or to a service using the bus, such as Avahi or NetworkManager, possibly causing the daemon to exit or the service to disconnect from the bus. (CVE-2011-2200) All users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. For the update to take effect, all running instances of dbus-daemon and all running applications using the libdbus library must be restarted, or the system rebooted. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 712676 - CVE-2011-2200 dbus: Local DoS via messages with non-native byte order 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: dbus-1.1.2-16.el5_7.i386.rpm dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-libs-1.1.2-16.el5_7.i386.rpm dbus-x11-1.1.2-16.el5_7.i386.rpm x86_64: dbus-1.1.2-16.el5_7.i386.rpm dbus-1.1.2-16.el5_7.x86_64.rpm dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-debuginfo-1.1.2-16.el5_7.x86_64.rpm dbus-libs-1.1.2-16.el5_7.i386.rpm dbus-libs-1.1.2-16.el5_7.x86_64.rpm dbus-x11-1.1.2-16.el5_7.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-devel-1.1.2-16.el5_7.i386.rpm x86_64: dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-debuginfo-1.1.2-16.el5_7.x86_64.rpm dbus-devel-1.1.2-16.el5_7.i386.rpm dbus-devel-1.1.2-16.el5_7.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: dbus-1.1.2-16.el5_7.i386.rpm dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-devel-1.1.2-16.el5_7.i386.rpm dbus-libs-1.1.2-16.el5_7.i386.rpm dbus-x11-1.1.2-16.el5_7.i386.rpm ia64: dbus-1.1.2-16.el5_7.ia64.rpm dbus-debuginfo-1.1.2-16.el5_7.ia64.rpm dbus-devel-1.1.2-16.el5_7.ia64.rpm dbus-libs-1.1.2-16.el5_7.ia64.rpm dbus-x11-1.1.2-16.el5_7.ia64.rpm ppc: dbus-1.1.2-16.el5_7.ppc.rpm dbus-1.1.2-16.el5_7.ppc64.rpm dbus-debuginfo-1.1.2-16.el5_7.ppc.rpm dbus-debuginfo-1.1.2-16.el5_7.ppc64.rpm dbus-devel-1.1.2-16.el5_7.ppc.rpm dbus-devel-1.1.2-16.el5_7.ppc64.rpm dbus-libs-1.1.2-16.el5_7.ppc.rpm dbus-libs-1.1.2-16.el5_7.ppc64.rpm dbus-x11-1.1.2-16.el5_7.ppc.rpm s390x: dbus-1.1.2-16.el5_7.s390.rpm dbus-1.1.2-16.el5_7.s390x.rpm dbus-debuginfo-1.1.2-16.el5_7.s390.rpm dbus-debuginfo-1.1.2-16.el5_7.s390x.rpm dbus-devel-1.1.2-16.el5_7.s390.rpm dbus-devel-1.1.2-16.el5_7.s390x.rpm dbus-libs-1.1.2-16.el5_7.s390.rpm dbus-libs-1.1.2-16.el5_7.s390x.rpm dbus-x11-1.1.2-16.el5_7.s390x.rpm x86_64: dbus-1.1.2-16.el5_7.i386.rpm dbus-1.1.2-16.el5_7.x86_64.rpm dbus-debuginfo-1.1.2-16.el5_7.i386.rpm dbus-debuginfo-1.1.2-16.el5_7.x86_64.rpm dbus-devel-1.1.2-16.el5_7.i386.rpm dbus-devel-1.1.2-16.el5_7.x86_64.rpm dbus-libs-1.1.2-16.el5_7.i386.rpm dbus-libs-1.1.2-16.el5_7.x86_64.rpm dbus-x11-1.1.2-16.el5_7.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: i386: dbus-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-x11-1.2.24-5.el6_1.i686.rpm x86_64: dbus-1.2.24-5.el6_1.x86_64.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.x86_64.rpm dbus-x11-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm noarch: dbus-doc-1.2.24-5.el6_1.noarch.rpm x86_64: dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: dbus-1.2.24-5.el6_1.x86_64.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.x86_64.rpm dbus-x11-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: noarch: dbus-doc-1.2.24-5.el6_1.noarch.rpm x86_64: dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: dbus-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-x11-1.2.24-5.el6_1.i686.rpm ppc64: dbus-1.2.24-5.el6_1.ppc64.rpm dbus-debuginfo-1.2.24-5.el6_1.ppc.rpm dbus-debuginfo-1.2.24-5.el6_1.ppc64.rpm dbus-devel-1.2.24-5.el6_1.ppc.rpm dbus-devel-1.2.24-5.el6_1.ppc64.rpm dbus-libs-1.2.24-5.el6_1.ppc.rpm dbus-libs-1.2.24-5.el6_1.ppc64.rpm dbus-x11-1.2.24-5.el6_1.ppc64.rpm s390x: dbus-1.2.24-5.el6_1.s390x.rpm dbus-debuginfo-1.2.24-5.el6_1.s390.rpm dbus-debuginfo-1.2.24-5.el6_1.s390x.rpm dbus-devel-1.2.24-5.el6_1.s390.rpm dbus-devel-1.2.24-5.el6_1.s390x.rpm dbus-libs-1.2.24-5.el6_1.s390.rpm dbus-libs-1.2.24-5.el6_1.s390x.rpm dbus-x11-1.2.24-5.el6_1.s390x.rpm x86_64: dbus-1.2.24-5.el6_1.x86_64.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.x86_64.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.x86_64.rpm dbus-x11-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): Source: noarch: dbus-doc-1.2.24-5.el6_1.noarch.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: dbus-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-x11-1.2.24-5.el6_1.i686.rpm x86_64: dbus-1.2.24-5.el6_1.x86_64.rpm dbus-debuginfo-1.2.24-5.el6_1.i686.rpm dbus-debuginfo-1.2.24-5.el6_1.x86_64.rpm dbus-devel-1.2.24-5.el6_1.i686.rpm dbus-devel-1.2.24-5.el6_1.x86_64.rpm dbus-libs-1.2.24-5.el6_1.i686.rpm dbus-libs-1.2.24-5.el6_1.x86_64.rpm dbus-x11-1.2.24-5.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: noarch: dbus-doc-1.2.24-5.el6_1.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2200 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. . A moderate security notification has been released concerning a dbus update for Red Hat Enterprise Linux aimed at resolving a denial of service vulnerability.. Red Hat Enterprise Linux,D-Bus Security Update,DoS Mitigation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.