CVE-2020-35512 - CVE House
Back to Database
Status published High CVE-2020-35512

A use-after-free flaw was found in D-Bus Development branch <=...

Vulnerability Description

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-35512

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

D-Bus Development branch, dbus-1.12.x stable branch, dbus-1.10.x and older branches (EOL)
Vulnerable Versions:
<= 1.13.16 (Fixed: >= 1.13.18), <= 1.12.18 (Fixed: >= 1.12.20), <= 1.10.30 (Fixed: 1.10.32)

Timeline

Official Publish: February 15th, 2021
Last Modified: November 19th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.