*** This bug is a security vulnerability ***

Public security bug reported:

https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-
pwcq-wvpq

> An incorrect implementation of message filtering in xdg-dbus-proxy versions 
> before 0.1.9 allows an attacker to bypass the intended message filtering on 
> the D-Bus session bus by setting a reply serial number on non-reply messages.
>
> xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, 
> but it is released as a separate project and is sometimes used by other app 
> frameworks such as Firejail.

Please see the upstream advisory for fix commits.

(Or just update to 0.1.9: the nature of this project is that basically
every line of code is either security-sensitive, or an automated test
for something that is security-sensitive.)

** Affects: xdg-dbus-proxy (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

** CVE added: https://cve.org/CVERecord?id=CVE-2026-94422

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168468

Title:
  CVE-2026-94422: Message filtering bypass via reply serial

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/xdg-dbus-proxy/+bug/2168468/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to