CVE-2024-1930 is a denial-of-service vulnerability affecting dnf5daemon-server before version 5.1.17, part of rpm-software-management dnf5. A malicious local user can exploit the lack of a session limit to exhaust system resources by creating numerous D-Bus sessions, each spawning a new thread and consuming significant memory. This leads to service unavailability as further connections become impossible. Rated Medium severity (CVSS 6.5), the vulnerability has a low attack complexity but a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.1.17CPE matchmatch criteria | cpe:2.3:a:rpm-software-management:dnf5:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.