Permissions, Privileges, and Access Controls in D-Bus - CVE-2023-34969
Published: July 21, 2023
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the dbus-daemon when sending a reply message from the "bus driver". If a local privileged user (e.g. root) is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, another unprivileged user with the ability to connect to the same dbus-daemon can force the service to send an unreplyable message and perform a denial of service (DoS) attack.
Affected software
Isolation Segment
VMware Tanzu Application Service for VMs
OpenShift Pipelines
Migration Toolkit for Virtualization
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Netcool Operations Insight
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Cloud Pak for Watson AIOps
SmartFabric OS10
ObjectScale
Enterprise SONiC
Robotic Process Automation for Cloud Pak
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
VMware Tanzu Operations Manager
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
AMQ Broker
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dbus (Ubuntu package)
libdbus-1-3 (Ubuntu package)
dbus-1-devel-doc
dbus-1-devel
libdbus-1-3-32bit
libdbus-1-3-debuginfo-32bit
dbus-1-x11-debuginfo
dbus-1-debugsource
dbus-1-debuginfo
dbus-1
dbus-1-x11-debugsource
libdbus-1-3
dbus-1-x11
libdbus-1-3-debuginfo
dbus-1-32bit-debuginfo
libdbus-1-3-32bit-debuginfo
dbus-1-devel-32bit
dbus (Red Hat package)
dbus-x11
dbus
dbus-tools
dbus-libs
dbus-devel
dbus-daemon
dbus-doc
dbus-common
dbus-debugsource
dbus-help
dbus-debuginfo
mingw-dbus
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
Dell EMC VxRail Appliance
How to mitigate CVE-2023-34969
Dell EMC PowerProtect Data Protection - update to 2.7.8
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Red Hat OpenShift Serverless - update to 1.30.1
OpenShift API for Data Protection (OADP) - update to 1.1.6
Migration Toolkit for Containers - update to 1.7.12
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7, 2.3.2
OpenShift Service Mesh - addressed in versions 2.2.10, 2.2.11, 2.3.8, 2.4.3, 2.4.4
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.7.7
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.0.5
OpenShift Virtualization - addressed in versions 4.11.7, 4.12.8, 4.13.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.3
Red Hat OpenShift Container Platform - update to 4.13.9
OpenShift Logging - addressed in versions 5.5.16, 5.6.11, 5.7.6
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat Migration Toolkit for Applications - update to 6.2.1
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
AMQ Broker - update to 7.11.1
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
dbus (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libdbus-1-3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.12
dbus-1-devel-doc - addressed in versions 1.8.22-44.1, 1.12.2-150400.18.8.1
dbus-1-devel - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
libdbus-1-3-32bit - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
libdbus-1-3-debuginfo-32bit - update to 1.8.22-44.1
dbus-1-x11-debuginfo - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-debugsource - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-debuginfo - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1 - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-x11-debugsource - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
libdbus-1-3 - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-x11 - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
libdbus-1-3-debuginfo - addressed in versions 1.8.22-44.1, 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-32bit-debuginfo - addressed in versions 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
libdbus-1-3-32bit-debuginfo - addressed in versions 1.12.2-150100.8.17.1, 1.12.2-150400.18.8.1
dbus-1-devel-32bit - update to 1.12.2-150400.18.8.1
dbus (Red Hat package) - addressed in versions 1.12.8-18.el8_6.3, 1.12.8-24.el8_8.1, 1.12.20-7.el9_2.1
dbus-x11 - update to 1.12.8-25.0.1
dbus - update to 1.12.8-25.0.1
dbus-tools - update to 1.12.8-25.0.1
dbus-libs - update to 1.12.8-25.0.1
dbus-devel - update to 1.12.8-25.0.1
dbus-daemon - update to 1.12.8-25.0.1
dbus-doc - update to 1.12.8-25.0.1
dbus-common - update to 1.12.8-25.0.1
dbus-debugsource - update to 1.12.16-20
dbus - update to 1.12.16-20
dbus-help - update to 1.12.16-20
dbus-common - update to 1.12.16-20
dbus-daemon - update to 1.12.16-20
dbus-x11 - update to 1.12.16-20
dbus-devel - update to 1.12.16-20
dbus-tools - update to 1.12.16-20
dbus-libs - update to 1.12.16-20
dbus-debuginfo - update to 1.12.16-20
dbus - update to 1.12.28-1
mingw-dbus - update to 1.14.8-1.fc38
VMware Tanzu Operations Manager - update to 2.10.62
IBM Cloud Transformation Advisor - update to 3.7.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Enterprise SONiC - update to 4.2.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 8.0.120
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
External References
Related Security Bulletins
- Local denial of service in D-Bus
- SUSE update for dbus-1
- SUSE update for dbus-1
- SUSE update for dbus-1
- Red Hat Enterprise Linux 8 update for dbus
- Red Hat Enterprise Linux 9 update for dbus
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Fedora 38 update for mingw-dbus
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in AMQ Broker 7.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in Logging Subsystem for Red Hat OpenShift
- Ubuntu update for dbus
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.4
- Red Hat Enterprise Linux 8.6 Extended Update Support update for dbus
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Logging Subsystem 5.5 for Red Hat OpenShift
- Multiple vulnerabilities in Logging Subsystem 5.6 for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- VMware Tanzu products update for DBus
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh for 2.4
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.5
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.0
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in Node Health Check Operator 0.6
- Multiple vulnerabilities in Node Health Check Operator 0.4
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.11
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- openEuler update for dbus
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for dbus
- Anolis OS update for dbus
- PowerProtect Data Protection software update for third-party components
- Meinberg LANTIME firmware update for third-party components (January 2024)
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)