Local Denial of Service Vulnerability in Dbus-broker by Red Hat
CVE-2026-16730

5.5MEDIUM

What is CVE-2026-16730?

A vulnerability in dbus-broker allows a local attacker to exploit the process file-descriptor limit. When this limit is reached, any errors during peer setup, such as EMFILE or ENFILE, can cause the broker to terminate unexpectedly. This results in a denial of service for the desktop session, particularly impacting users who rely on Flatpak applications that connect to the session bus via the dbus proxy.

Affected Version(s)

Red Hat Enterprise Linux 10 0:36-5.el10_2

Red Hat Enterprise Linux 9 0:28-9.el9_8

Red Hat Update Infrastructure 5 1788880445

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Josh Simmons for reporting this issue.
.