{"id":"AZL-66105","summary":"CVE-2024-1930 affecting package dnf5 for versions less than 5.0.14-3","details":"No Limit on Number of Open Sessions / Bad Session Close Behaviour  in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open Sessions.\n\nThere is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method. For each session a thread is created in dnf5daemon-server. This spends a couple of hundred megabytes of memory in the process. Further connections will become impossible, likely because no more threads can be spawned by the D-Bus service.\n\n","modified":"2026-04-21T04:37:46.704411Z","published":"2024-05-08T02:15:09Z","upstream":["CVE-2024-1930"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1930"}],"affected":[{"package":{"name":"dnf5","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/dnf5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.14-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66105.json"}}],"schema_version":"1.7.5"}