Impact
The vulnerability allows an unauthenticated local or remote attacker to send excessively long data streams to the GDBus authentication mechanism, which does not enforce length limits on input lines. This can cause the targeted GDBus service to consume large amounts of memory and CPU, leading to application crashes or system hangs. The weakness is a classic example of unsanitized input that overwhelms the application, classified under CWE-770.
Affected Systems
Affected Red Hat products include Red Hat Enterprise Linux versions 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. All these distributions ship a GLib library that contains the vulnerable GDBus implementation. Upgrades to newer GLib releases that include the fix are required for protection.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1 % indicates an extremely low likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, suggesting no widely known or actively used exploits at this time. However, the lack of input validation provides a straightforward path for an attacker to cause resource exhaustion. The potential for denial‑of‑service in critical services warrants prompt remediation.
OpenCVE Enrichment