Use-after-free in D-Bus - CVE-2020-35512
Published: May 9, 2022
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error if two usernames have the same numeric UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, which can result in crash.
Affected software
cflinuxfs3
Platform Automation Toolkit
Business Automation Insights
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Pak for Business Automation
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
libdbus-1-3-debuginfo-32bit
dbus-1
dbus-1-debuginfo
dbus-1-debuginfo-32bit
dbus-1-debugsource
dbus-1-x11
dbus-1-x11-debuginfo
dbus-1-x11-debugsource
libdbus-1-3
libdbus-1-3-32bit
libdbus-1-3-debuginfo
dbus-1-devel-doc
dbus-1-devel
libdbus-1-3 (Ubuntu package)
dbus (Ubuntu package)
libdbus-1-3-32bit-debuginfo
dbus-1-32bit-debuginfo
dbus-debuginfo
dbus-debugsource
dbus
dbus-tools
dbus-devel
dbus-daemon
dbus-libs
dbus-x11
dbus-help
dbus-common
Dell EMC VxRail Appliance
How to mitigate CVE-2020-35512
cflinuxfs3 - update to 0.294.0
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13
Platform Automation Toolkit - addressed in versions 4.0.13, 4.1.13, 4.2.8, 4.3.5
Business Automation Insights - update to 25.0.0.0.1
libdbus-1-3-debuginfo-32bit - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2
dbus-1 - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-debuginfo - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-debuginfo-32bit - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1
dbus-1-debugsource - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-x11 - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-x11-debuginfo - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-x11-debugsource - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
libdbus-1-3 - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
libdbus-1-3-32bit - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
libdbus-1-3-debuginfo - addressed in versions 1.8.22-24.22.1, 1.8.22-29.21.1, 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-devel-doc - update to 1.8.22-35.2
dbus-1-devel - addressed in versions 1.8.22-35.2, 1.12.2-3.11.1, 1.12.2-8.6.1
libdbus-1-3 (Ubuntu package) - addressed in versions 1.10.61ubuntu3.6+esm1, 1.12.2-1ubuntu1.3, 1.12.16-2ubuntu2.2
dbus (Ubuntu package) - addressed in versions 1.10.61ubuntu3.6+esm1, 1.12.2-1ubuntu1.3, 1.12.16-2ubuntu2.2
libdbus-1-3-32bit-debuginfo - addressed in versions 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-1-32bit-debuginfo - addressed in versions 1.12.2-3.11.1, 1.12.2-8.6.1
dbus-debuginfo - update to 1.12.16-16
dbus-debugsource - update to 1.12.16-16
dbus - update to 1.12.16-16
dbus-tools - update to 1.12.16-16
dbus-devel - update to 1.12.16-16
dbus-daemon - update to 1.12.16-16
dbus-libs - update to 1.12.16-16
dbus-x11 - update to 1.12.16-16
dbus-help - update to 1.12.16-16
dbus-common - update to 1.12.16-16
Dell EMC VxRail Appliance - update to 7.0.203
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
External References
Related Security Bulletins
- Denial of service in D-Bus
- Ubuntu update for dbus
- Multiple vulnerabilities in cflinuxfs3
- SUSE update for dbus-1
- SUSE update for dbus-1
- SUSE update for dbus-1
- SUSE update for dbus-1
- Ubuntu update for dbus
- VMware Tanzu products update for DBus
- SUSE update for dbus-1
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- openEuler update for dbus
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation