Description
No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions.

There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.

Published: 2024-05-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-17652 No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.
History

Thu, 07 Aug 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Rpm-software-management
Rpm-software-management dnf5
CPEs cpe:2.3:a:rpm-software-management:dnf5:*:*:*:*:*:*:*:*
Vendors & Products Rpm-software-management
Rpm-software-management dnf5

Subscriptions

Fedora Dnf5daemon-server
Rpm-software-management Dnf5
cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-08-01T18:56:22.475Z

Reserved: 2024-02-27T12:44:59.949Z

Link: CVE-2024-1930

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.475Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-08T02:15:09.503

Modified: 2025-08-07T17:21:11.740

Link: CVE-2024-1930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T16:01:29Z

Weaknesses