CVE-2022-42012

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*
cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

History

09 Jun 2025, 15:15

Type Values Removed Values Added
CWE CWE-20

Information

Published : 2022-10-10 00:15

Updated : 2025-06-09 15:15


NVD link : CVE-2022-42012

Mitre link : CVE-2022-42012

CVE.ORG link : CVE-2022-42012


JSON object : View

Products Affected

freedesktop

  • dbus

fedoraproject

  • fedora
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation