Red HatCVE-2026-16730
Red Hat dbus-broker.: improper exception handling
Medium5.5CVE-2026-16730 · Published Jul 24, 2026 · updated Sep 10, 2026
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Hardened Images Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-755
- www.cve.org/CVERecord?id=CVE-2026-16730
- nvd.nist.gov/vuln/detail/CVE-2026-16730
- access.redhat.com/errata/RHSA-2026:61340
- access.redhat.com/errata/RHSA-2026:61355
- access.redhat.com/errata/RHSA-2026:66018
- access.redhat.com/security/cve/CVE-2026-16730
- bugzilla.redhat.com/show_bug.cgi?id=2506348
- github.com/bus1/dbus-broker/issues/435
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 24 | Red Hat libsoup: request smuggling | Medium5.4 | No fix yet |
| Jul 24 | Red Hat libsoup: information disclosure | Medium6.5 | No fix yet |
| Jul 24 | Red Hat libsoup. An unsigned integer underflow: integer overflow | Medium6.5 | No fix yet |
| Jul 24 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat... | High8.5 | No fix yet |
| Jul 24 | Red Hat pki-core: improper authorization | Low3.1 | No fix yet |
| Jul 24 | Red Hat role-users endpoint: insecure direct object reference | Medium6.5 | No fix yet |