Security Advisory Desk
mediumQCS priority 76/100Microsoft

CVE-2026-4948: Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

A security issue affects firewalld, a firewall management tool used in some Microsoft-supported Linux distributions, where a local unprivileged user can improperly change the firewall state due to incorrect authorization handling in a system communication interface called d-bus. This can allow unauthorized changes to firewall settings, potentially impacting system security. Microsoft recommends checking their Security Update Guide to see if your system is affected and to apply updates accordingly.

QCS published 4/10/2026, 12:12:37 am ISTVendor disclosure 10/3/2026, 12:30:00 pm ISTVerified 4/10/2026, 12:12:37 am ISTRevision 1

In plain language

What this advisory means

A security issue affects firewalld, a firewall management tool used in some Microsoft-supported Linux distributions, where a local unprivileged user can improperly change the firewall state due to incorrect authorization handling in a system communication interface called d-bus. This can allow unauthorized changes to firewall settings, potentially impacting system security. Microsoft recommends checking their Security Update Guide to see if your system is affected and to apply updates accordingly.

Technical explanation

How the issue affects the environment

The vulnerability involves firewalld versions 1.0.3-2 (on CBL-Mariner 2.0) and 2.0.2-3 (on Azure Linux 3.0), where a d-bus setter method lacks proper authorization checks. This mis-authorization enables a local unprivileged user to modify firewall state information by invoking d-bus setters without sufficient permissions. Corrected versions, such as firewalld 2.0.2-4 and updated CBL-Mariner releases, include fixes that enforce proper permission validation on these d-bus interfaces.

Operational impact

Why teams should care

Unauthorized local changes to firewall configurations can lead to weakened network defenses, exposing systems to increased risk of unauthorized network access or disruption. Organizations relying on affected firewalld versions on respective Microsoft Linux distributions must address this vulnerability to maintain their security postures and compliance requirements.

Immediate action

Review Microsoft’s Security Update Guide for full applicability and detailed remediation instructions. Apply the updated firewalld packages: version 2.0.2-4 for Azure Linux and the corresponding updated releases for CBL-Mariner. Follow official upgrade procedures linked in Microsoft documentation.

Affected and fixed releases

Affected versionscbl2 firewalld 1.0.3-2 on CBL Mariner 2.0, azl3 firewalld 2.0.2-3 on Azure Linux 3.0
Fixed versionsazl3 firewalld 2.0.2-4, CBL-Mariner Releases

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Microsoft Security Response Center advisory for CVE-2026-4948
  • Listed affected and fixed versions
  • Severity and CVSS score provided
  • Official remediation update links

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source