CVE-2014-3635: D-Bus Project D-Bus

Medium severity, CVSS 4.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.

Affected products

  • D-Bus Project D-Bus: up to and including 1.6.22
  • Freedesktop Dbus: version 1.6.0 only; version 1.6.2 only; version 1.6.4 only; version 1.6.6 only; version 1.6.8 only; version 1.6.10 only; …
  • Opensuse Opensuse: version 12.3 only

Published 2014-09-22. Last modified 2026-06-17.