Skip to content

CVE-2014-3532

dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0012 (0.1%)
Percentile: 30.9%
EPSS: 2026-05-06

Affects

freedesktop:dbuslinux:linux_kernelopensuse:opensusedebian:debian_linuxmageia:mageiaoracle:solaris

Technical description

dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

Published: 7/19/2014, 7:55:07 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam