CVE-2026-16730
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.11%
- CWE
- CWE-755
- Published
- 2026-07-24
- Last modified
- 2026-09-10
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
- Red Hat Red Hat Update Infrastructure 5
Weakness type
Related vulnerabilities
- CVE-2026-49305 — Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation...
- CVE-2026-45819 — baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or...
- CVE-2026-52856 — Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
- CVE-2026-59952 — Valibot: record() issue paths can make flatten() throw for inherited Object property names
- CVE-2026-42792 — epmd permanent DoS via EMFILE on accept(2) in erts
- CVE-2026-48036 — Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
- CVE-2026-62994 — CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
- CVE-2026-59162 — Excelize: Negative shared-string index causes panic in GetCellValue and GetRows