CVE-2015-0245: Freedesktop Dbus

Low severity, CVSS 1.9. EPSS: 0.3% chance of exploitation in the next 30 days.

D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.

Affected products

  • Freedesktop Dbus: version 1.4.0 only; version 1.4.1 only; version 1.4.4 only; version 1.4.6 only; version 1.4.8 only; version 1.4.10 only; …
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-02-13. Last modified 2026-06-17.