Back

MEDIUM

gnome-session: Bad reference counting in accept_ice_connection() permits resource exhaustion

Published Jul 11, 2017

Description

Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie). Each failed authentication attempt will leak a file descriptor in gnome-session. When the maximum number of file descriptors is exhausted in the gnome-session process, it will enter an infinite loop trying to communicate without success, consuming 100% of the CPU. The graphical session associated with the gnome-session process will stop working correctly, because communication with gnome-session is no longer possible.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 11, 2017
Updated Sep 17, 2024
Reserved Jul 11, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 11, 2017