{"id":"JLSEC-2025-21","summary":"An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before ...","details":"An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.","modified":"2025-11-06T23:03:12.781352Z","published":"2025-10-10T14:27:45.619Z","upstream":["CVE-2022-42012"],"database_specific":{"sources":[{"url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-42012","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42012","imported":"2025-10-10T13:32:22.006Z","id":"CVE-2022-42012","modified":"2025-06-09T15:15:28.623Z","published":"2022-10-10T00:15:09.627Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://gitlab.freedesktop.org/dbus/dbus/-/issues/417"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4CO7N226I3X5FNBR2MACCH6TS764VJP/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ND74SKN56BCYL3QLEAAB6E64UUBRA5UG/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SQCSLMCK2XGX23R2DKW2MSAICQAK6MT2/"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-08"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2022/10/06/1"}],"affected":[{"package":{"name":"Dbus_jll","ecosystem":"Julia","purl":"pkg:julia/Dbus_jll?uuid=ee1fde0b-3d02-5ea6-8484-8dfef6360eab"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.14.10+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-21.json"}}],"schema_version":"1.7.3"}