[Pkg-utopia-maintainers] Bug#1148782: xdg-dbus-proxy: CVE-2026-94422: Message filtering bypass via reply serial (GHSA-2cgv-pwcq-wvpq)
Simon McVittie
smcv at debian.org
Wed Sep 23 15:01:22 BST 2026
Package: xdg-dbus-proxy
Version: 0.1.0-1
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
>An incorrect implementation of message filtering in xdg-dbus-proxy
>versions before 0.1.9 allows an attacker to bypass the intended message
>filtering on the D-Bus session bus by setting a reply serial number on
>non-reply messages.
>
>xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak,
>but it is released as a separate project and is sometimes used by other
>app frameworks such as Firejail.
>
>Impact:
>
>A malicious or compromised Flatpak app could achieve arbitrary code
>execution outside its sandbox.
>
>If other app frameworks rely on xdg-dbus-proxy in the same way that
>Flatpak does, then they will have an equivalent vulnerability until
>xdg-dbus-proxy is updated.
>
>Workarounds:
>
>Avoid running untrusted Flatpak apps.
>
>Avoid running untrusted apps via other frameworks that use xdg-dbus-proxy.
More information about the Pkg-utopia-maintainers
mailing list