From 0531ae1dcc79f7866d158cb0a978432f3c1429d3 Mon Sep 17 00:00:00 2001 From: Simon McVittie Date: Tue, 6 Jun 2023 12:04:03 +0100 Subject: [PATCH] Update NEWS Signed-off-by: Simon McVittie (cherry picked from commit 05367daa101247b1b5f7648b635cbe47eb220b39) --- NEWS | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index a1a6c13c..87545da1 100644 --- a/NEWS +++ b/NEWS @@ -1,7 +1,16 @@ dbus 1.12.27 (UNRELEASED) ========================= -Fixes: +Denial-of-service fixes: + +• Fix an assertion failure in dbus-daemon when a privileged Monitoring + connection (dbus-monitor, busctl monitor, gdbus monitor or similar) + is active, and a message from the bus driver cannot be delivered to a + client connection due to rules or outgoing message quota. This + is a denial of service if triggered maliciously by a local attacker. + (dbus#457; hongjinghao, Simon McVittie) + +Other fixes: • Documentation: · Fix syntax of a code sample in dbus-api-design