CVE-2022-42012: Input Validation
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-42012?
CVE-2022-42012 is a vulnerability discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2.
How does CVE-2022-42012 affect D-Bus?
CVE-2022-42012 allows an authenticated attacker to crash dbus-daemon and other programs that use libdbus by sending a message with attached file descriptors in an unexpected format.
What is the severity of CVE-2022-42012?
CVE-2022-42012 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2022-42012?
D-Bus versions before 1.12.24, between 1.13.0 and 1.14.4, and between 1.15.0 and 1.15.2 are affected by CVE-2022-42012.
How can I fix CVE-2022-42012?
To fix CVE-2022-42012, update D-Bus to version 1.12.24 or higher, 1.14.4 or higher, or 1.15.2 or higher.