PT-2024-18432 · Unknown · Dnf5Daemon-Server
Matthias Gerstner
·
Published
2024-03-07
·
Updated
2024-05-08
·
CVE-2024-1930
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
dnf5daemon-server versions prior to 5.1.17
Description
The issue allows a malicious user to impact availability by creating an unlimited number of sessions using the
open session() D-Bus method. For each session, a thread is created in dnf5daemon-server, consuming a significant amount of memory. This can lead to a situation where further connections become impossible, likely due to the D-Bus service being unable to spawn additional threads.Recommendations
For versions prior to 5.1.17, update to version 5.1.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the
open session() D-Bus method to minimize the risk of exploitation.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dnf5Daemon-Server