Skip to content

libdbus CVE-2022-42011

Moderate
etungsten published GHSA-x5mr-fh4p-5vc7 Nov 17, 2022

Package

libdbus (bottlerocket)

Affected versions

< 1.11.0

Patched versions

1.11.0

Description

An authenticated attacker could cause dbus-daemon and other programs that use libdbus to crash when receiving a message whose array length is inconsistent with the size of the element type.

Severity

Moderate

CVE ID

CVE-2022-42011

Weaknesses

No CWEs