USN-5244-2: DBus vulnerability
9 May 2022
DBus could be made to crash if it received specially crafted input.
- dbus - simple interprocess messaging system
USN-5244-1 fixed a vulnerability in DBus. This update provides
the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
Daniel Onaca discovered that DBus contained a use-after-free vulnerability,
caused by the incorrect handling of usernames sharing the same UID. An
attacker could possibly use this issue to cause DBus to crash, resulting
in a denial of service.
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to reboot your computer to make
all the necessary changes.
- USN-5244-1: dbus-tests, libdbus-1-3, dbus, libdbus-1-dev, dbus-x11, dbus-user-session, dbus-1-doc