CVE-2022-42010: Medium severity IBM Data Virtualization on Cloud Pak for Data vulnerability
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Other sources
Freedesktop D-Bus is vulnerable to a denial of service, caused by an assertion failure. By sending a specially-crafted message using invalid type signature with incorrectly nested parentheses and curly brackets, a local attacker could exploit this vulnerability to cause a crash or incorrect message processing, and results in a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-42010?
CVE-2022-42010 is a vulnerability in D-Bus that allows an authenticated attacker to crash dbus-daemon and other programs using libdbus by sending a message with certain invalid type signatures.
What is the severity of CVE-2022-42010?
The severity of CVE-2022-42010 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2022-42010?
D-Bus versions before 1.12.24, between 1.13.0 and 1.14.4, and between 1.15.0 and 1.15.2 are affected. Fedora versions 35, 36, and 37 are also affected.
How can an attacker exploit CVE-2022-42010?
An attacker with authentication can exploit CVE-2022-42010 by sending a specially crafted message with invalid type signatures to dbus-daemon or other programs using libdbus, causing them to crash.
Is there a fix for CVE-2022-42010?
Yes, upgrading to D-Bus version 1.12.24, 1.14.4, or 1.15.2 and updating Fedora to a version higher than 37 will fix the vulnerability.