Impact
The flaw in dbus‑broker is a resource exhaustion weakness (CWE‑755). When the process file‑descriptor limit is reached, EMFILE/ENFILE errors that occur during peer setup—particularly involving SO_PEERPIDFD—are handled as fatal failures, causing the broker to exit. This local denial of service interrupts the desktop session for the affected user.
Affected Systems
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images and Red Hat OpenShift Container Platform 4 all ship the vulnerable dbus‑broker component. The flaw affects the session bus process running under these distributions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Attacks require local access to the user session bus and sufficient privileges to open many connections, so the risk is limited to compromised local users but any such compromise would deny service to the entire desktop session.
OpenCVE Enrichment