Description
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
0.14 (custom) before unknown
Credits
Matthias Gerstner of SUSE
References
www.openwall.com/lists/oss-security/2026/05/11/1
security.opensuse.org/...5/11/malcontent-disk-space-dos.html
bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44931