Control: tags -1 + pending

On Wed, 23 Sep 2026 at 15:01:22 +0100, Simon McVittie wrote:
An incorrect implementation of message filtering in xdg-dbus-proxy
versions before 0.1.9 allows an attacker to bypass the intended message
filtering on the D-Bus session bus by setting a reply serial number on
non-reply messages.

Proposed update for trixie:
https://salsa.debian.org/debian/xdg-dbus-proxy/-/commits/debian/trixie-proposed

Source and binary test-build (functionally equivalent
to what I propose, only differs in the changelog):
https://people.debian.org/~smcv/temp/2026/CVE-2026-94422/

If the LTS team looks at this: the changes might well apply cleanly to older x-d-p versions, but I haven't tried. Or backporting a whole newer x-d-p would also be reasonable - basically the whole thing is security-sensitive, so you won't gain much by isolating security fixes.

    smcv

Reply via email to