Any version with commit 0297845 is vulnerable, meaning versions 0.1.6
and 0.1.7, together with any version to which that change was
backported.

Ubuntu 26.04 'resolute' is likely to be vulnerable.

Older Ubuntu is probably not vulnerable.

The solution is to revert commit 0297845. Note that this may cause
regressions unless app frameworks are updated appropriately: for example
this will cause a regression for Flatpak >= 1.15.9 unless the solution
for that regression is backported from 1.18.1. Debian's 1.16.6-1~deb13u2
has a backported fix for this.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167727

Title:
  CVE-2026-93676: filtering for broadcast messages bypassing
  path/interface/member checks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/xdg-dbus-proxy/+bug/2167727/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to