CVE-2020-35512
Summary
| CVE | CVE-2020-35512 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-15 17:15:00 UTC |
| Updated | 2023-12-27 16:36:00 UTC |
| Description | A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1909101 – (CVE-2020-35512) CVE-2020-35512 dbus: users with the same numeric UID could lead to use-after-free and undefined behaviour |
MISC |
bugzilla.redhat.com |
|
| Dangling pointer access in dbus-userdb.c (#305) · Issues · dbus / dbus · GitLab |
MISC |
gitlab.freedesktop.org |
|
| 755392 – (CVE-2020-35512) <sys-apps/dbus-1.12.20: use after free if duplicate UIDs (CVE-2020-35512) |
MISC |
bugs.gentoo.org |
Issue Tracking, Third Party Advisory |
| CVE-2020-35512 |
MISC |
security-tracker.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198777 Ubuntu Security Notification for DBus Vulnerability (USN-5244-2)
- 6140164 AWS Bottlerocket Security Update for libdbus (GHSA-m7gr-wq6g-x327)
- 670482 EulerOS Security Update for dbus (EulerOS-SA-2021-2240)
- 670508 EulerOS Security Update for dbus (EulerOS-SA-2021-2266)
- 672184 EulerOS Security Update for dbus (EulerOS-SA-2022-2455)
- 672244 EulerOS Security Update for dbus (EulerOS-SA-2022-2605)
- 672319 EulerOS Security Update for dbus (EulerOS-SA-2022-2708)
- 750737 SUSE Enterprise Linux Security Update for dbus-1 (SUSE-SU-2021:2211-1)
- 750752 SUSE Enterprise Linux Security Update for dbus-1 (SUSE-SU-2021:2292-1)
- 750755 OpenSUSE Security Update for dbus-1 (openSUSE-SU-2021:2292-1)
- 750855 OpenSUSE Security Update for dbus-1 (openSUSE-SU-2021:1056-1)
- 750870 SUSE Enterprise Linux Security Update for dbus-1 (SUSE-SU-2021:2424-1)
- 750909 SUSE Enterprise Linux Security Update for dbus-1 (SUSE-SU-2021:2590-1)