[From nobody Wed Sep 23 15:51:04 2026
Received: (at submit) by bugs.debian.org; 23 Sep 2026 14:01:26 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-118.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,
 DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FROMDEVELOPER,FVGT_m_MULTI_ODD,
 HAS_PACKAGE,SPF_HELO_NONE,SPF_PASS,USER_IN_DKIM_WELCOMELIST
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 18; hammy, 148; neutral, 42; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;smcv@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:52296)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x9NXK-005YqF-1P
 for submit@bugs.debian.org; Wed, 23 Sep 2026 14:01:26 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Type:MIME-Version:Message-ID:
 Subject:To:From:Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=ViIS7x1/RAcCBp7QO45SRUI2SG8n6vD3/fidwKTJxbs=; b=RmxXO23jAYuhgE1aqG18C3CPX0
 VJx7kn+vqvg/l4nQyU5I9oo5kas/j2m/2JAG3z5n2cPGIc8GeJQmmBorO2nGym/AcMHSGYS179Gy+
 H7kxdKzdoyzwTbd6pMACIH7UJ/g6yszEftU6JVrcgFSG+5MWdkz0QoazeocdTAD58s/nucQ04op3A
 0R1cPhQdTDRVjpmNXIGF1QgcIjpbGKTmZzJIBYeT/OAf5C/SqsdELac0X86tFGA/n9k+JE8qupmvv
 W9rfZD3+jLmjqgef9Od1kDWcFQ1DT3ftq1Mc1HHfJp9SPdEzI9b5Aw25V0aOqkBdPrFOSQQnF+3Hi
 gmLEbbJg==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1x9NXI-003nyH-2N
 for submit@bugs.debian.org; Wed, 23 Sep 2026 14:01:25 +0000
Date: Wed, 23 Sep 2026 15:01:22 +0100
From: Simon McVittie &lt;smcv@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: xdg-dbus-proxy: CVE-2026-94422: Message filtering bypass via reply
 serial (GHSA-2cgv-pwcq-wvpq)
Message-ID: &lt;arPbsh0hGI8CN4o_@definition.pseudorandom.co.uk&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Mutt-Fcc: =.lists.debian/
X-Reportbug-Version: 13.2.0+nmu1
X-Debian-User: smcv
Delivered-To: submit@bugs.debian.org

Package: xdg-dbus-proxy
Version: 0.1.0-1
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq

&gt;An incorrect implementation of message filtering in xdg-dbus-proxy
&gt;versions before 0.1.9 allows an attacker to bypass the intended message
&gt;filtering on the D-Bus session bus by setting a reply serial number on
&gt;non-reply messages.
&gt;
&gt;xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak,
&gt;but it is released as a separate project and is sometimes used by other
&gt;app frameworks such as Firejail.
&gt;
&gt;Impact:
&gt;
&gt;A malicious or compromised Flatpak app could achieve arbitrary code
&gt;execution outside its sandbox.
&gt;
&gt;If other app frameworks rely on xdg-dbus-proxy in the same way that
&gt;Flatpak does, then they will have an equivalent vulnerability until
&gt;xdg-dbus-proxy is updated.
&gt;
&gt;Workarounds:
&gt;
&gt;Avoid running untrusted Flatpak apps.
&gt;
&gt;Avoid running untrusted apps via other frameworks that use xdg-dbus-proxy.
]