Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A `GDBus` authentication denial-of-service / resource exhaustion flaw has been reported. The vulnerability involves a lack of line length limitations when `gdbusauth` reads input from a client. This can be exploited by an unauthenticated remote or local attacker to cause excessive memory and CPU consumption.
This was fixed upstream in 2.88.3 and 2.89.2. Fedora 45 and 44 are not affected (glib 2.89.3 and 2.88.3 respectively). Although Fedora 43 is affected (glib 2.86.5), the CVE is considered low impact in practice. Furthermore, Fedora 43 will EOL on December 9, so no fix is planned.
*** Bug 2500601 has been marked as a duplicate of this bug. ***