CVE-2023-34969: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only
  • Freedesktop Dbus: from 1.12.0, before 1.12.28 (fixed in 1.12.28); from 1.14.0, before 1.14.8 (fixed in 1.14.8); from 1.15.0, before 1.15.6 (fixed in 1.15.6)

Published 2023-06-08. Last modified 2026-06-17.