
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39959 is a set of vulnerabilities in the .NET D-Bus libraries Tmds.DBus and Tmds.DBus.Protocol that allow malicious peers on the same D-Bus to spoof signals, exhaust system resources, and crash applications. Affected versions include Tmds.DBus < 0.92.0 and Tmds.DBus.Protocol < 0.21.3 (and >= 0.22.0, < 0.92.0). The advisory was published on April 8, 2026, and assigned CVE-2026-39959 on April 9, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, GHSA).
The vulnerability encompasses three distinct attack classes rooted in insufficient input validation and missing resource controls in the D-Bus message handling logic. First, signal spoofing (CWE-290: Authentication Bypass by Spoofing) allows a local peer to impersonate the owner of a well-known D-Bus name and send fraudulent signals to other bus participants. Second, resource exhaustion (CWE-400/CWE-770: Uncontrolled Resource Consumption / Allocation Without Limits) is possible by sending messages carrying an excessive number of Unix file descriptors, leading to file descriptor spillover and system resource depletion. Third, denial of service is achievable by crafting malformed D-Bus message bodies that trigger unhandled exceptions on the application's SynchronizationContext, crashing the process. All three attack vectors require only local bus access with low privileges and no user interaction (GitHub Advisory, GHSA).
Successful exploitation can result in high integrity impact — through spoofed D-Bus signals that may cause consuming applications to act on falsified data — and high availability impact via application crashes or system-wide file descriptor exhaustion. Confidentiality is not directly impacted. Applications relying on D-Bus for inter-process communication (IPC) on Linux systems using these .NET libraries are at risk, and integrity compromise through signal spoofing could potentially be leveraged to influence privileged service behavior on the same bus (GitHub Advisory, GHSA).
dbus-send, gdbus, or a custom .NET D-Bus client) to connect to the same session or system bus as the target application.org.example.Service), causing the vulnerable library to accept and process the forged signal as legitimate.SynchronizationContext, crashing the target process (GHSA).SynchronizationContext in .NET processes using Tmds.DBus; D-Bus daemon logs (/var/log/syslog or journalctl) showing unusual message patterns from unexpected senders./proc/<pid>/fd showing near-maximum open descriptors).dbus-monitor) showing signals from unexpected senders claiming ownership of well-known names, or messages with unusually high numbers of attached file descriptors (GHSA).Patches are available and upgrading is the only remediation — no known workarounds exist. Users of Tmds.DBus should upgrade to version 0.92.0. Users of Tmds.DBus.Protocol should upgrade to 0.21.3 (backport) or 0.92.0. Update NuGet package references in project files and rebuild/redeploy affected applications (GitHub Advisory, GHSA).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."