5.5

CVE-2026-4948

Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Firewalld ≫ Firewalld Version <= 2.4.0
Redhat ≫ Enterprise Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-279 Incorrect Execution-Assigned Permissions

While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.

https://bugzilla.redhat.com/show_bug.cgi?id=2452086
Vendor Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2026/05/msg00029.html
https://access.redhat.com/security/cve/CVE-2026-4948
Vendor Advisory
Mitigation
https://access.redhat.com/errata/RHBA-2026:28238
https://access.redhat.com/errata/RHSA-2026:67585
https://access.redhat.com/errata/RHSA-2026:67843
https://access.redhat.com/errata/RHSA-2026:76844