Skip to content

libdbus CVE-2022-42012

Moderate
etungsten published GHSA-rr99-8x9w-6hr2 Nov 17, 2022

Package

libdbus (bottlerocket)

Affected versions

< 1.11.0

Patched versions

1.11.0

Description

An authenticated attacker could cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Severity

Moderate

CVE ID

CVE-2022-42012

Weaknesses

No CWEs