PT-2026-64278 · Unknown+1 · Dbus-Broker+1

CVE-2026-16730

·

Published

2026-07-24

·

Updated

2026-08-31

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions dbus-broker (affected versions not specified)
Description A flaw exists where EMFILE/ENFILE errors, which occur when the process file-descriptor limit is reached during peer setup (specifically involving SO PEERPIDFD), are treated as fatal failures. This causes the broker to exit. A local attacker can trigger this condition by opening numerous connections to the user session bus, resulting in a denial of service for the desktop session. Flatpak applications can facilitate this by reaching the host session bus through the dbus proxy.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61340
ALSA-2026:61355
CVE-2026-16730
RHSA-2026:61340
RHSA-2026:61355

Affected Products

Rocky Linux
Dbus-Broker