Bug 1172505 (CVE-2020-12049) - VUL-1: CVE-2020-12049: dbus-1: truncated messages lead to resource exhaustion
Summary: VUL-1: CVE-2020-12049: dbus-1: truncated messages lead to resource exhaustion
Status: RESOLVED FIXED
Alias: CVE-2020-12049
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/260692/
Whiteboard: CVSSv3.1:SUSE:CVE-2020-12049:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-04 09:12 UTC by Wolfgang Frisch
Modified: 2024-07-09 10:03 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-06-04 09:12:37 UTC
CVE-2020-12049

In D-Bus, MSG_CTRUNC indicates that we have received fewer fds that we
should have done because the buffer was too small, but we were
treating it as though it indicated that we received *no* fds. If we
received any, we still have to make sure we close them, otherwise they
will be leaked.

On the system bus, if an attacker can induce us to leak fds in this
way, that's a local denial of service via resource exhaustion.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-12049
http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-12049.html
https://security-tracker.debian.org/tracker/CVE-2020-12049
https://gitlab.freedesktop.org/dbus/dbus/-/commit/272d484283883fa9ff95b69d924fff6cd34842f5
https://gitlab.freedesktop.org/dbus/dbus/-/commit/8bc1381819e5a845331650bfa28dacf6d2ac1748
Comment 1 Wolfgang Frisch 2020-06-25 18:10:58 UTC
SUSE:SLE-11-SP1:Update   Not affected [1]
SUSE:SLE-12:Update       Affected
SUSE:SLE-12-SP3:Update   Affected
SUSE:SLE-12-SP5:Update   Affected
SUSE:SLE-15-SP1:Update   Affected
SUSE:SLE-15:Update       Affected

[1] The file descriptor leak was introduced by commit 4c4db7f9da1aa29c264a9f9d7d9fb1d774e28ee1
Comment 10 Swamp Workflow Management 2021-07-21 14:00:38 UTC
SUSE-SU-2021:2424-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1172505,1187105
CVE References: CVE-2020-12049,CVE-2020-35512
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    dbus-1-1.8.22-35.2, dbus-1-x11-1.8.22-35.2
SUSE Linux Enterprise Server 12-SP5 (src):    dbus-1-1.8.22-35.2, dbus-1-x11-1.8.22-35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2021-07-27 13:19:55 UTC
SUSE-SU-2021:2470-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1172505
CVE References: CVE-2020-12049
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15 (src):    dbus-1-1.12.2-3.16.1, dbus-1-x11-1.12.2-3.16.1
SUSE Linux Enterprise Server 15-LTSS (src):    dbus-1-1.12.2-3.16.1, dbus-1-x11-1.12.2-3.16.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    dbus-1-1.12.2-3.16.1, dbus-1-x11-1.12.2-3.16.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    dbus-1-1.12.2-3.16.1, dbus-1-x11-1.12.2-3.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2021-08-02 16:15:44 UTC
SUSE-SU-2021:2590-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1172505,1187105
CVE References: CVE-2020-12049,CVE-2020-35512
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE OpenStack Cloud Crowbar 8 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE OpenStack Cloud 9 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE OpenStack Cloud 8 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1
HPE Helion Openstack 8 (src):    dbus-1-1.8.22-29.21.1, dbus-1-x11-1.8.22-29.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Marcus Meissner 2021-08-09 15:08:29 UTC
done
Comment 15 Swamp Workflow Management 2021-08-23 13:17:51 UTC
# maintenance_jira_update_notice
openSUSE-SU-2021:2810-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172505
CVE References: CVE-2020-12049
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    dbus-1-1.12.2-8.11.2, dbus-1-x11-1.12.2-8.11.1
Comment 16 Swamp Workflow Management 2021-08-23 13:28:29 UTC
# maintenance_jira_update_notice
SUSE-SU-2021:2810-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172505
CVE References: CVE-2020-12049
JIRA References: 
Sources used:
SUSE MicroOS 5.0 (src):    dbus-1-1.12.2-8.11.2
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    dbus-1-1.12.2-8.11.2, dbus-1-x11-1.12.2-8.11.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    dbus-1-1.12.2-8.11.2, dbus-1-x11-1.12.2-8.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2021-08-26 22:18:53 UTC
# maintenance_jira_update_notice
openSUSE-SU-2021:1204-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172505
CVE References: CVE-2020-12049
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    dbus-1-1.12.2-lp152.6.6.1, dbus-1-x11-1.12.2-lp152.6.6.1
Comment 19 Simon Lees 2023-06-19 10:14:49 UTC
this should now be in all streams
Comment 20 Wolfgang Frisch 2024-07-09 10:03:43 UTC
Released