Any version with commit 0297845 is vulnerable, meaning versions 0.1.6 and 0.1.7, together with any version to which that change was backported.
Ubuntu 26.04 'resolute' is likely to be vulnerable. Older Ubuntu is probably not vulnerable. The solution is to revert commit 0297845. Note that this may cause regressions unless app frameworks are updated appropriately: for example this will cause a regression for Flatpak >= 1.15.9 unless the solution for that regression is backported from 1.18.1. Debian's 1.16.6-1~deb13u2 has a backported fix for this. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167727 Title: CVE-2026-93676: filtering for broadcast messages bypassing path/interface/member checks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xdg-dbus-proxy/+bug/2167727/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
