A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade dbus | Jul 30, 2024 | Feb 15, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade dbus-x11Upgrade dbus-develUpgrade dbus-libsUpgrade dbus | Oct 28, 2022 | Feb 15, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade dbusUpgrade dbus-develUpgrade dbus-libsUpgrade dbus-x11 | Nov 4, 2022 | Feb 15, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade dbusUpgrade dbus-daemonUpgrade dbus-libsUpgrade dbus-develUpgrade dbus-x11Upgrade dbus-toolsUpgrade dbus-common | Oct 11, 2022 | Feb 15, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade dbus-daemonUpgrade dbus-commonUpgrade dbus-libsUpgrade dbusUpgrade dbus-tools | Aug 10, 2021 | Feb 15, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 15, 2021 |
| Suse | — | Upgrade dbus-1-devel-docUpgrade dbus-1-devel-32bitUpgrade libdbus-1-3Upgrade libdbus-1-3-32bitUpgrade dbus-1Upgrade dbus-1-x11Upgrade dbus-1-devel | Jul 1, 2021 | Feb 15, 2021 |
| Ubuntu | — | Upgrade dbus (Ubuntu Pro)Upgrade libdbus-1-3 (Ubuntu Pro)Upgrade dbusUpgrade libdbus-1-3 | Jan 21, 2022 | Feb 15, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub