PT-2025-45972 · Julia · Dbus Jll

Published

2025-10-10

·

Updated

2025-10-10

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-18

Affected Products

Dbus Jll