Local Denial of Service Vulnerability in Dbus-broker by Red Hat
CVE-2026-16730
5.5MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-16730?
A vulnerability in dbus-broker allows a local attacker to exploit the process file-descriptor limit. When this limit is reached, any errors during peer setup, such as EMFILE or ENFILE, can cause the broker to terminate unexpectedly. This results in a denial of service for the desktop session, particularly impacting users who rely on Flatpak applications that connect to the session bus via the dbus proxy.
Affected Version(s)
Red Hat Enterprise Linux 10 0:36-5.el10_2
Red Hat Enterprise Linux 9 0:28-9.el9_8
Red Hat Update Infrastructure 5 1788880445
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Josh Simmons for reporting this issue.