Red Hat dbus-broker是美国Red Hat公司开源的一款专为 Linux 系统设计的高性能 D-Bus 消息代理。 Red Hat dbus-broker存在异常处理不当漏洞,该漏洞源于异常处理不当,当进程文件描述符限制达到时,对等体设置(特别是SO_PEERPIDFD)期间出现的EMFILE/ENFILE错误被视为致命错误,导致客户端退出,本地攻击者可通过打开多个到用户会话总线的连接触发此问题,拒绝服务到桌面会话。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:36-5.el10_2< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:28-9.el9_8< * |
unaffected |
| Red Hat | Red Hat Hardened Images | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
| Red Hat | Red Hat Update Infrastructure 5 | 1788880445< * |
unaffected |
1788880464< * |
unaffected | ||
1788880456< * |
unaffected | ||
1788765051< * |
unaffected | ||
1788880581< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:36-5.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:28-9.el9_8 ~ * |
cpe:/o:redhat:enterprise_linux:9::baseos
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1788880445 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1788880464 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1788880456 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1788765051 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1788880581 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17107 | 8.5 HIGH | Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluste |
| CVE-2026-66337 | 6.5 MEDIUM | Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_ |
| CVE-2026-66339 | 6.5 MEDIUM | Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization hea |
| CVE-2026-17059 | 6.5 MEDIUM | Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypas |
| CVE-2026-17048 | 5.5 MEDIUM | Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via adm |
| CVE-2026-16743 | 5.5 MEDIUM | Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed us |
| CVE-2026-16910 | 5.5 MEDIUM | Quay: ssrf in red hat quay notification webhooks (slack/generic) |
| CVE-2026-66338 | 5.4 MEDIUM | Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_in |
| CVE-2026-17039 | 3.1 LOW | Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm auth |
No comments yet