Fedora Account System
Red Hat Associate
Red Hat Customer
The GLib D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. The D-Bus specification explicitly states that cookie context names must not contain the characters /, \, . (period), spaces, or ASCII control characters. However, GLib's client-side code accepts this value verbatim and uses it to construct a filesystem path via g_build_filename(). A malicious D-Bus server can supply a cookie_context containing path traversal sequences such as ../.target_file, causing the client to read an arbitrary file outside the ~/.dbus-keyrings/ directory. The file contents (specifically the third space-separated token of the first matching line) are then incorporated into a SHA1 hash computation and sent back to the server as part of the authentication response. The server can verify guessed file contents against this SHA1 hash, enabling data exfiltration.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:49512 https://access.redhat.com/errata/RHSA-2026:49512
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55440 https://access.redhat.com/errata/RHSA-2026:55440
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57015 https://access.redhat.com/errata/RHSA-2026:57015
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:61766 https://access.redhat.com/errata/RHSA-2026:61766
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:65762 https://access.redhat.com/errata/RHSA-2026:65762
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:65771 https://access.redhat.com/errata/RHSA-2026:65771
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:65767 https://access.redhat.com/errata/RHSA-2026:65767
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:65769 https://access.redhat.com/errata/RHSA-2026:65769
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:65763 https://access.redhat.com/errata/RHSA-2026:65763
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:65773 https://access.redhat.com/errata/RHSA-2026:65773
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:65768 https://access.redhat.com/errata/RHSA-2026:65768
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:65770 https://access.redhat.com/errata/RHSA-2026:65770
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:66357 https://access.redhat.com/errata/RHSA-2026:66357