Back

MEDIUM

dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly

Published Oct 9, 2022

Description

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 9, 2022
Updated Jun 9, 2025
Reserved Oct 3, 2022
CISA Vulnrichment
Updated Jan 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 5, 2022