A dbus security update has been released for AlmaLinux 8.
ALSA-2023:0096 Moderate: dbus security update
Type:
security
Severity:
moderate
Release date:
2023-01-13
Description
Security Fix(es):
* dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)
* dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)
* dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
RHSA-2023:0096
CVE-2022-42010
CVE-2022-42011
CVE-2022-42012
ALSA-2023:0096
Updates packages:
dbus-devel-1.12.8-23.el8_7.1.i686.rpm
dbus-libs-1.12.8-23.el8_7.1.i686.rpm
dbus-common-1.12.8-23.el8_7.1.noarch.rpm
dbus-tools-1.12.8-23.el8_7.1.aarch64.rpm
dbus-libs-1.12.8-23.el8_7.1.aarch64.rpm
dbus-daemon-1.12.8-23.el8_7.1.aarch64.rpm
dbus-1.12.8-23.el8_7.1.aarch64.rpm
dbus-tools-1.12.8-23.el8_7.1.x86_64.rpm
dbus-1.12.8-23.el8_7.1.x86_64.rpm
dbus-daemon-1.12.8-23.el8_7.1.x86_64.rpm
dbus-daemon-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-libs-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-tools-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-devel-1.12.8-23.el8_7.1.aarch64.rpm
dbus-x11-1.12.8-23.el8_7.1.aarch64.rpm
dbus-x11-1.12.8-23.el8_7.1.x86_64.rpm
dbus-daemon-1.12.8-23.el8_7.1.s390x.rpm
dbus-1.12.8-23.el8_7.1.s390x.rpm
dbus-tools-1.12.8-23.el8_7.1.s390x.rpm
dbus-libs-1.12.8-23.el8_7.1.s390x.rpm
dbus-x11-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-devel-1.12.8-23.el8_7.1.ppc64le.rpm
dbus-x11-1.12.8-23.el8_7.1.s390x.rpm
dbus-devel-1.12.8-23.el8_7.1.s390x.rpm
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.