*** This bug is a security vulnerability *** Public security bug reported:
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv- pwcq-wvpq > An incorrect implementation of message filtering in xdg-dbus-proxy versions > before 0.1.9 allows an attacker to bypass the intended message filtering on > the D-Bus session bus by setting a reply serial number on non-reply messages. > > xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, > but it is released as a separate project and is sometimes used by other app > frameworks such as Firejail. Please see the upstream advisory for fix commits. (Or just update to 0.1.9: the nature of this project is that basically every line of code is either security-sensitive, or an automated test for something that is security-sensitive.) ** Affects: xdg-dbus-proxy (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security ** CVE added: https://cve.org/CVERecord?id=CVE-2026-94422 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168468 Title: CVE-2026-94422: Message filtering bypass via reply serial To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xdg-dbus-proxy/+bug/2168468/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
