firewalld is a firewall service daemon that provides a dynamic customizable firewall with a D-Bus interface.
Security Fix(es):
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.(CVE-2026-4948)
{
"severity": "Medium"
}