[Pkg-utopia-maintainers] Bug#1148782: xdg-dbus-proxy: CVE-2026-94422: Message filtering bypass via reply serial (GHSA-2cgv-pwcq-wvpq)

Simon McVittie smcv at debian.org
Wed Sep 23 15:47:21 BST 2026


Control: tags -1 + pending

On Wed, 23 Sep 2026 at 15:01:22 +0100, Simon McVittie wrote:
>>An incorrect implementation of message filtering in xdg-dbus-proxy
>>versions before 0.1.9 allows an attacker to bypass the intended message
>>filtering on the D-Bus session bus by setting a reply serial number on
>>non-reply messages.

Proposed update for trixie:
https://salsa.debian.org/debian/xdg-dbus-proxy/-/commits/debian/trixie-proposed

Source and binary test-build (functionally equivalent
to what I propose, only differs in the changelog):
https://people.debian.org/~smcv/temp/2026/CVE-2026-94422/

If the LTS team looks at this: the changes might well apply cleanly to 
older x-d-p versions, but I haven't tried. Or backporting a whole newer 
x-d-p would also be reasonable - basically the whole thing is 
security-sensitive, so you won't gain much by isolating security fixes.

     smcv



More information about the Pkg-utopia-maintainers mailing list