<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:22:07 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:61340 — Moderate: dbus-broker security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:61340</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: dbus-broker&lt;/p&gt;
&lt;p&gt;dbus-broker is an implementation of a message bus as defined by the D-Bus specification. Its aim is to provide high performance and reliability, while keeping compatibility to the D-Bus reference implementation. It is exclusively written for Linux systems, and makes use of many modern features provided by recent Linux kernel releases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup (CVE-2026-16730)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: dbus-broker&lt;/p&gt;
&lt;p&gt;dbus-broker is an implementation of a message bus as defined by the D-Bus specification. Its aim is to provide high performance and reliability, while keeping compatibility to the D-Bus reference implementation. It is exclusively written for Linux systems, and makes use of many modern features provided by recent Linux kernel releases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup (CVE-2026-16730)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:61340</guid>
    </item>
    <item>
      <title>EUVD-2026-366501</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366501</link>
      <description>EUVD-2026-366501</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366501</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16730</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16730</link>
      <description>&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16730</guid>
    </item>
    <item>
      <title>GHSA-77qf-9j4m-ph58</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-77qf-9j4m-ph58</link>
      <description>&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-77qf-9j4m-ph58</guid>
    </item>
    <item>
      <title>RHSA-2026:61340 — Red Hat Security Advisory: dbus-broker security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:61340</link>
      <description>&lt;p&gt;dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:61340</guid>
    </item>
    <item>
      <title>RHSA-2026:66018 — Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:66018</link>
      <description>&lt;p&gt;curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via specially crafted long inputs attr: attr: Symlink Traversal Privilege Escala…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via specially crafted long inputs attr: attr: Symlink Traversal Privilege Escala…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:66018</guid>
    </item>
    <item>
      <title>RLSA-2026:61340 — Moderate: dbus-broker security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:61340</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dbus-broker&lt;/p&gt;
&lt;p&gt;dbus-broker is an implementation of a message bus as defined by the D-Bus specification. Its aim is to provide high performance and reliability, while keeping compatibility to the D-Bus reference implementation. It is exclusively written for Linux systems, and makes use of many modern features provided by recent Linux kernel releases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup (CVE-2026-16730)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dbus-broker&lt;/p&gt;
&lt;p&gt;dbus-broker is an implementation of a message bus as defined by the D-Bus specification. Its aim is to provide high performance and reliability, while keeping compatibility to the D-Bus reference implementation. It is exclusively written for Linux systems, and makes use of many modern features provided by recent Linux kernel releases.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dbus-broker: dbus-broker: session bus denial of service via EMFILE during peer setup (CVE-2026-16730)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:61340</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-16730</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16730</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dbus-broker, Ubuntu:24.04:LTS: dbus-broker, Ubuntu:26.04:LTS: dbus-broker&lt;/p&gt;
&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dbus-broker, Ubuntu:24.04:LTS: dbus-broker, Ubuntu:26.04:LTS: dbus-broker&lt;/p&gt;
&lt;p&gt;A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16730</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3095 — Red Hat Enterprise Linux (pipewire,dbus-broker): Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3095</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3095</guid>
    </item>
  </channel>
</rss>
