[Git][security-tracker-team/security-tracker][master] CVE-2026-93676/xdg-dbus-proxy assigned (GHSA-r7hp-698j-2h6c)

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 21:16:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2197a8ce by Salvatore Bonaccorso at 2026-09-18T22:15:49+02:00
CVE-2026-93676/xdg-dbus-proxy assigned (GHSA-r7hp-698j-2h6c)

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -56,8 +56,6 @@ CVE-2026-93687 (braces through 3.0.3 contains a stack overflow vulnerability in
 	NOTE: https://github.com/micromatch/braces/issues/70
 CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A remote att ...)
 	NOT-FOR-US: multicluster-observability-addon (Red Hat Advanced Cluster Management for Kubernetes 2)
-CVE-2026-93676 (xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing ...)
-	TODO: check
 CVE-2026-93660 (SQLBot through 1.10.1 fails to verify dashboard ownership in update_re ...)
 	TODO: check
 CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders customer-supplied or ...)
@@ -53530,9 +53528,8 @@ CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/9b990351898b18b48bf4e834bcbc618d270cf8b1 (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/85f241ef6b3784257f0278c4dfbd988355921862 (branch flatpak-1.16.x)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b0f1704b34d2a551c0073a9fc5e918174a97af64 (branch flatpak-1.16.x)
-CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
+CVE-2026-93676 [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
 	- xdg-dbus-proxy 0.1.8-1 (bug #1144129)
-	[trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
 	[bookworm] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
 	[bullseye] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c


=====================================
data/DSA/list
=====================================
@@ -215,6 +215,7 @@
 	{CVE-2026-12804 CVE-2026-19349}
 	[trixie] - lemonldap-ng 2.21.2+ds-1+deb13u3
 [12 Aug 2026] DSA-6433-1 xdg-dbus-proxy - security update
+	{CVE-2026-93676}
 	[trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
 [12 Aug 2026] DSA-6432-1 flatpak - security update
 	{CVE-2026-90616}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2197a8ce5818d70d61ce8781e33afd98bcc8f79f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2197a8ce5818d70d61ce8781e33afd98bcc8f79f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/64208e40/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list