Skip to main content
Version: latest

CVE-2020-35512

CVE Details

CVE-2020-35512

Last Update

9/25/24

NIST CVE Summary

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors

Our Official Summary

This vulnerability is reported on several 3rd party images used by our product. A new fixed version of the image is available by upgrading to 4.4.18.

CVE Severity

7.8

Status

Ongoing

Affected Products & Versions

  • Palette VerteX airgap 4.4.14

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
  • 3.0 9/25/2024 CVE remediated in Palette VerteX airgap 4.4.18