PT-2026-31658 · Tmds.Dbus+1 · Tmds.Dbus+1
CVE-2026-39959
·
Published
2026-04-08
·
Updated
2026-04-09
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tmds.DBus versions prior to 0.92.0
Tmds.DBus.Protocol versions prior to 0.92.0 and 0.21.3
Description
Tmds.DBus and Tmds.DBus.Protocol are susceptible to attacks from malicious D-Bus peers. An attacker on the same bus can impersonate the owner of a well-known name to spoof signals, exhaust system resources or cause file descriptor spillover by sending messages containing an excessive number of Unix file descriptors, and crash the application by sending malformed message bodies that trigger unhandled exceptions on the SynchronizationContext.
Recommendations
Upgrade Tmds.DBus to version 0.92.0 or later.
Upgrade Tmds.DBus.Protocol to version 0.92.0 or 0.21.3 or later.
Exploit
Fix
Resource Exhaustion
Authentication Bypass by Spoofing
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tmds.Dbus
Tmds.Dbus.Protocol