5.5
CVE-2026-16730
- EPSS 0.11%
- Veröffentlicht 24.07.2026 11:26:18
- Zuletzt bearbeitet 10.09.2026 18:17:56
- Erkennungen
Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 10
Default Statusaffected
Version
0:36-5.el10_2
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 9
Default Statusaffected
Version
0:28-9.el9_8
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Update Infrastructure 5
Default Statusaffected
Version
1788880445
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Update Infrastructure 5
Default Statusaffected
Version
1788880464
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Update Infrastructure 5
Default Statusaffected
Version
1788880456
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Update Infrastructure 5
Default Statusaffected
Version
1788765051
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Update Infrastructure 5
Default Statusaffected
Version
1788880581
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat Hardened Images
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift Container Platform 4
Default Statusaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.013 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
https://access.redhat.com/security/cve/CVE-2026-16730
https://bugzilla.redhat.com/show_bug.cgi?id=2506348
https://github.com/bus1/dbus-broker/issues/435
https://access.redhat.com/errata/RHSA-2026:61340
https://access.redhat.com/errata/RHSA-2026:61355
https://access.redhat.com/errata/RHSA-2026:66018