Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16730

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.

Отчет

A Moderate severity flaw in dbus-broker enables a local attacker or a Flatpak application within the same user session to induce a denial of service. This occurs when dbus-broker exhausts its file-descriptor table and exits instead of rejecting new connections, leading to a session bus crash and desktop disruption. Exploitation requires local access or a compromised application in the same user session.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dbus-brokerAffected
Red Hat Enterprise Linux 9dbus-brokerAffected
Red Hat Hardened Imagesdbus-brokerAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-755
https://bugzilla.redhat.com/show_bug.cgi?id=2506348dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup

EPSS

Процентиль: 1%
0.00107
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
24 дня назад

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.

CVSS3: 5.5
nvd
24 дня назад

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.

CVSS3: 5.5
debian
24 дня назад

A flaw was found in dbus-broker. When the process file-descriptor limi ...

CVSS3: 5.5
github
24 дня назад

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.

EPSS

Процентиль: 1%
0.00107
Низкий

5.5 Medium

CVSS3