← לוח פגיעויות

CVE-2026-4948

בינונית 5.5

תיאור (מקור, אנגלית)

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.

מדדים

CVSS 3.1
5.5 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-23/9/2026
CWE
CWE-279

מוצרים מושפעים

firewalld: firewalld; redhat: enterprise linux

קישורים