CVE-2020-12049: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
  • Freedesktop Dbus: from 1.3.0, before 1.12.18 (fixed in 1.12.18)

Published 2020-06-08. Last modified 2026-06-17.