CVE-2026-4948: Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
Other sources
firewalld <=2.4.0 appears to mis-authorize two runtime D-Bus setters, setZoneSettings2 and setPolicySettings, by guarding them with PKACTIONCONFIGINFO. When the shipped desktop policy is active, that appears to let a local unprivileged user modify runtime firewall state without authentication. The attacker needs to have local, unprivileged access to a system with firewalld using the desktop profile of firewalld.
— Red Hat
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.2-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4948?
CVE-2026-4948 is considered a medium severity vulnerability due to its potential to allow local unprivileged users to modify firewall settings.
How do I fix CVE-2026-4948?
To fix CVE-2026-4948, update the firewalld package to a version later than 2.4.0 where the vulnerability has been resolved.
Who is affected by CVE-2026-4948?
CVE-2026-4948 affects systems running firewalld version 2.4.0 and earlier.
What impact does CVE-2026-4948 have on my system?
CVE-2026-4948 allows local unprivileged users to modify the firewall state, which can lead to security breaches.
Is there a workaround for CVE-2026-4948?
A potential workaround for CVE-2026-4948 is to restrict access to the D-Bus service until a patch is applied.