CVE-2026-44931 Details
Description
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd
A disk space exhaustion vulnerability has been identified in Malcontent version 0.14.0, specifically within the 'malcontent-timerd' component. This issue arises from a newly introduced D-Bus method called 'RecordUsage', which allows arbitrary users to gradually consume disk space in the '/var/lib/malcontent-timerd' directory. The vulnerability can be exploited by sending repeated requests to the D-Bus method, each of which creates an entry in a database file associated with the user's account. This accumulation of data entries leads to a local denial-of-service condition by filling up available disk space.
As of now, there is no official patch available for this vulnerability. However, it has been suggested that the D-Bus method could be restricted to local active session callers and that a limit could be imposed on the number of usage entries each user account can generate.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |
| May 13, 2026 | CVE Modified | CVE |