Use-after-close vulnerability in dbus-broker 35. Please upgrade package to 36

Bug #2061155 reported by XA Hydra
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
dbus-broker (Ubuntu)
New
Undecided
Unassigned

Bug Description

Per https://github.com/bus1/dbus-broker/releases/tag/v36 :

# dbus-broker - Linux D-Bus Message Broker

## CHANGES WITH 36:

    * Fix possible file-descriptor use-after-close, which can lead to
      broker termination or disclosure of internal file-desciptors to
      clients.

ProblemType: Bug
DistroRelease: Ubuntu 24.04
Package: dbus-broker 35-2
ProcVersionSignature: Ubuntu 6.8.0-22.22-generic 6.8.1
Uname: Linux 6.8.0-22-generic x86_64
ApportVersion: 2.28.0-0ubuntu1
Architecture: amd64
CasperMD5CheckResult: pass
CurrentDesktop: ubuntu:GNOME
Date: Fri Apr 12 11:24:50 2024
InstallationDate: Installed on 2024-04-08 (4 days ago)
InstallationMedia: Ubuntu 24.04 LTS "Noble Numbat" - Daily amd64 (20240407.2)
ProcEnviron:
 LANG=en_US.UTF-8
 PATH=(custom, no user)
 SHELL=/bin/bash
 TERM=xterm-256color
 XDG_RUNTIME_DIR=<set>
SourcePackage: dbus-broker
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
XA Hydra (xa-hydra) wrote :
Revision history for this message
Alex Murray (alexmurray) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

tags: added: community-security
information type: Private Security → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.