Description
No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions.
There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.
There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17652 | No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service. |
References
| Link | Providers |
|---|---|
| https://www.openwall.com/lists/oss-security/2024/03/04/2 |
|
History
Thu, 07 Aug 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rpm-software-management
Rpm-software-management dnf5 |
|
| CPEs | cpe:2.3:a:rpm-software-management:dnf5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rpm-software-management
Rpm-software-management dnf5 |
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-01T18:56:22.475Z
Reserved: 2024-02-27T12:44:59.949Z
Link: CVE-2024-1930
Updated: 2024-08-01T18:56:22.475Z
Status : Analyzed
Published: 2024-05-08T02:15:09.503
Modified: 2025-08-07T17:21:11.740
Link: CVE-2024-1930
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:29Z
Weaknesses
EUVD