Published
Permalink
CVE-2026-4948
5.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
by @mweinelt Activity log
- Created automatic suggestion
- @mweinelt removed package firewalld-gui
- @mweinelt accepted
- @mweinelt published on GitHub
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.
References
- https://access.redhat.com/security/cve/CVE-2026-4948 x_refsource_REDHAT vdb-entry
- RHBZ#2452086 issue-tracking x_refsource_REDHAT
Affected products
rhcos
firewalld
Matching in nixpkgs
Package maintainers
-
@Prince213 Sizhe Zhao <prc.zhao@outlook.com>