[Pkg-utopia-maintainers] Bug#1148782: xdg-dbus-proxy: CVE-2026-94422: Message filtering bypass via reply serial (GHSA-2cgv-pwcq-wvpq)
Simon McVittie
smcv at debian.org
Wed Sep 23 15:47:21 BST 2026
Control: tags -1 + pending
On Wed, 23 Sep 2026 at 15:01:22 +0100, Simon McVittie wrote:
>>An incorrect implementation of message filtering in xdg-dbus-proxy
>>versions before 0.1.9 allows an attacker to bypass the intended message
>>filtering on the D-Bus session bus by setting a reply serial number on
>>non-reply messages.
Proposed update for trixie:
https://salsa.debian.org/debian/xdg-dbus-proxy/-/commits/debian/trixie-proposed
Source and binary test-build (functionally equivalent
to what I propose, only differs in the changelog):
https://people.debian.org/~smcv/temp/2026/CVE-2026-94422/
If the LTS team looks at this: the changes might well apply cleanly to
older x-d-p versions, but I haven't tried. Or backporting a whole newer
x-d-p would also be reasonable - basically the whole thing is
security-sensitive, so you won't gain much by isolating security fixes.
smcv
More information about the Pkg-utopia-maintainers
mailing list