dbus-broker-28-9.el9_8
エラータID: AXSA:2026-1736:01
dbus-broker is an implementation of a message bus as defined by the D-Bus specification. Its aim is to provide high performance and reliability, while keeping compatibility to the D-Bus reference implementation. It is exclusively written for Linux systems, and makes use of many modern features provided by recent Linux kernel releases.
Security Fix(es):
* dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup (CVE-2026-16730)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-16730
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Update packages.
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
N/A
SRPMS
- dbus-broker-28-9.el9_8.src.rpm
MD5: bfe4855c99ac462bb3266f66e0cf7fae
SHA-256: d1beb2fee67d4c4bf9db44b377f973f7b23f8b0273bad975e527f366c33b7a2a
Size: 246.48 kB
Asianux Server 9 for x86_64
- dbus-broker-28-9.el9_8.x86_64.rpm
MD5: f4f0b95aa0fadbf307a9613fa01b550e
SHA-256: 5bcf38fae806dc81c5b227fb558563231079a233b68a017d4c64de6467d68ba7
Size: 169.05 kB