Oracle Linux 9 and 10 dbus-broker DoS Vulnerabilities Addressed

Oracle Linux 9 and 10 dbus-broker DoS Vulnerabilities Addressed

First seen 5 Sep 2026, 21:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Oracle has released patches for a moderate denial of service (DoS) vulnerability affecting the dbus-broker in both Oracle Linux 9 and 10. The vulnerability, identified as CVE-2026-16730, allows for a session bus DoS via EMFILE during peer setup. This affects users of Oracle Linux 9 and 10, specifically versions 28-9 and 36-5 of the dbus-broker package. The patches are crucial for maintaining system stability and security. Administrators are advised to apply the updates promptly to mitigate potential service disruptions. The vulnerability does not appear to be actively exploited at this time, but it is important to remain vigilant. Both advisories emphasize the importance of keeping systems up to date with the latest patches.

Key Points: • Moderate DoS vulnerability in dbus-broker for Oracle Linux 9 and 10. • CVE-2026-16730 allows session bus DoS via EMFILE during peer setup. • Patches released for affected versions; immediate application recommended.

Ask AI about this cluster

Timeline

2026-09-03
Oracle Linux 9 dbus-broker patch released
Oracle released ELSA-2026-61355 to fix the DoS vulnerability in dbus-broker for Oracle Linux 9.
Linuxsecurity
2026-09-05
Oracle Linux 10 dbus-broker patch released
Oracle released ELSA-2026-61340 to address the same DoS vulnerability in dbus-broker for Oracle Linux 10.
Linuxsecurity