Skip to content
Threat Feed
medium advisory

Denial of Service Vulnerabilities in RHEL pipewire and dbus-broker

Multiple vulnerabilities in the pipewire and dbus-broker components of Red Hat Enterprise Linux allow an attacker to trigger a Denial of Service condition through system instability or service disruption.

CVE search metadata

CVE search record: CVE-2024-5222. Severity: medium. CVSS: 6.4. EPSS: 0.32%. KEV: no. Product: Enterprise Linux, xmlrpc-c. Brief: Denial of Service Vulnerabilities in RHEL pipewire and dbus-broker. Brief link: https://feed.craftedsignal.io/briefs/2026-08-rhel-dos-vulnerabilities/

CVE search record: CVE-2024-5223. Severity: medium. CVSS: 6.4. EPSS: 0.33%. KEV: no. Product: Enterprise Linux, xmlrpc-c. Brief: Denial of Service Vulnerabilities in RHEL pipewire and dbus-broker. Brief link: https://feed.craftedsignal.io/briefs/2026-08-rhel-dos-vulnerabilities/

What's new

  • 1. added coverage for Enterprise Linux +1 products Aug 31, 11:58 via bsi

The German Federal Office for Information Security (BSI) has released an advisory regarding multiple vulnerabilities in Red Hat Enterprise Linux (RHEL). These vulnerabilities specifically affect the 'pipewire' multimedia framework and the 'dbus-broker' message bus implementation. An attacker can leverage these flaws to induce a Denial of Service (DoS) state, potentially resulting in system instability or the crash of critical background services. This impact is significant for production environments relying on these components for inter-process communication or audio-visual processing. Defenders should prioritize updating affected systems to the latest security releases provided by Red Hat to mitigate these risks.

Impact

Successful exploitation of these vulnerabilities leads to a Denial of Service (DoS) condition, which can cause service disruption or full system instability. The scope of targeting includes RHEL environments where pipewire and dbus-broker are active. If an attack succeeds, critical services relying on D-Bus or multimedia processing may become unresponsive, requiring manual intervention or a system reboot to restore normal operations.

Recommendation

Prioritize the application of security updates for RHEL systems to patch CVE-2024-5222 and CVE-2024-5223. IT Operations teams should monitor for unexpected crashes or service restarts of the 'pipewire' or 'dbus-broker' binaries as potential indicators of exploitation attempts or instability.

Mitigations

Upgrade RHEL components to the latest versions containing patches for CVE-2024-5222 and CVE-2024-5223.

immediate IT Operations

CVE-2024-5222, CVE-2024-5223