From f99e5de1ac13220ecde1e3b5ce66bef73f6a3e12 Mon Sep 17 00:00:00 2001 From: Simon McVittie Date: Tue, 6 Jun 2023 12:03:38 +0100 Subject: [PATCH] Update NEWS Signed-off-by: Simon McVittie (cherry picked from commit 05367daa101247b1b5f7648b635cbe47eb220b39) --- NEWS | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/NEWS b/NEWS index ae2a06f6..ddce98e4 100644 --- a/NEWS +++ b/NEWS @@ -1,7 +1,16 @@ dbus 1.14.8 (UNRELEASED) ======================== -Fixes: +Denial-of-service fixes: + +• Fix an assertion failure in dbus-daemon when a privileged Monitoring + connection (dbus-monitor, busctl monitor, gdbus monitor or similar) + is active, and a message from the bus driver cannot be delivered to a + client connection due to rules or outgoing message quota. This + is a denial of service if triggered maliciously by a local attacker. + (dbus#457; hongjinghao, Simon McVittie) + +Other fixes: • Fix compilation on compilers not supporting __FUNCTION__ (dbus!404, Barnabás Pőcze)