#1144129 xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks

Package:
xdg-dbus-proxy
Source:
xdg-dbus-proxy
Description:
filtering D-Bus proxy
Submitter:
Simon McVittie
Date:
2026-08-11 15:09:02 UTC
Severity:
normal
Tags:
#1144129#5
Date:
2026-08-11 12:24:35 UTC
From:
To:
In xdg-dbus-proxy versions 0.1.6 and 0.1.7 (only), filtering for
broadcast messages bypasses the intended path/interface/member checks. A
malicious or compromised Flatpak app could monitor any broadcast signal
on the D-Bus session bus or the AT-SPI bus, obtaining information that
was not intended to be available to it.

Similarly, if a non-Flatpak app framework uses

    xdg-dbus-proxy … --broadcast=…

or

    xdg-dbus-proxy … --call=…

then a compromised or malicious app in that framework could monitor
broadcast signals on the affected bus.

This is fixed in upstream release 0.1.8.

Note that fixing this may cause regressions unless app frameworks are
updated appropriately:

  * Flatpak versions 1.15.9 and up attempt to allow sandboxed apps to
    receive two broadcast signals on the AT-SPI bus, but the --broadcast
    command-line options that Flatpak passed to xdg-dbus-proxy were
    incorrect. As a result, fixing this vulnerability will regress
    accessibility features for Flatpak apps, unless Flatpak is also updated
    to correct its --broadcast rules. This is fixed in Flatpak versions
    1.18.1 and newer (coming soon) by commit
    "run-dbus: Correct --broadcast rules for the AT-SPI bus".
  * If a legitimate Flatpak app was relying on being able to receive
    broadcast signals from a service for which it did not have a --talk-name
    or --system-talk-name permission, this would accidentally have worked as
    a result of this vulnerability, but will fail after this vulnerability
    is fixed. This can be addressed by updating any affected Flatpak apps'
    metadata to request an appropriate --talk-name or --system-talk-name
    permission.
  * If other app frameworks use xdg-dbus-proxy, the framework or its apps
    might experience similar regressions, which can be addressed by adding
    suitable --broadcast or --talk rules to its xdg-dbus-proxy invocation.

Preparing 0.1.8-1 for unstable soon, and I've already contacted the
security team regarding a trixie backport.

    smcv

#1144129#10
Date:
2026-08-11 13:18:49 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
xdg-dbus-proxy, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144129@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated xdg-dbus-proxy package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 11 Aug 2026 13:32:52 +0100
Source: xdg-dbus-proxy
Architecture: source
Version: 0.1.8-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1144129
Changes:
 xdg-dbus-proxy (0.1.8-1) unstable; urgency=high
 .
   * New upstream release
     - Fix a vulnerability in access control for receiving broadcasts.
       In 0.1.6 and 0.1.7, a malicious or compromised Flatpak app could
       receive any broadcast D-Bus message on the session bus or the AT-SPI
       bus, leading to unintended information disclosure.
       (GHSA-r7hp-698j-2h6c, Closes: #1144129)
   * Mention #1132939 in previous changelog entry
Checksums-Sha1:
 d6799fbaa9f8a0a30d8840b19e1491b091cf41f9 2489 xdg-dbus-proxy_0.1.8-1.dsc
 af6ea4ef33583b518cb2945bc6d51c3d59226077 45932 xdg-dbus-proxy_0.1.8.orig.tar.xz
 254da82c0ab966757adea2fac3a51d55ded73422 4416 xdg-dbus-proxy_0.1.8-1.debian.tar.xz
 0cd1f3c9799f1b63f428e61111134448150524da 110888 xdg-dbus-proxy_0.1.8-1.git.tar.xz
 ffa7d4bc5b15d48c402f777c78241dd6305f736e 17580 xdg-dbus-proxy_0.1.8-1_source.buildinfo
Checksums-Sha256:
 6608f6d6ce803a431707a9f62bdc9be22fba6d7acc23425ea7f50e1dda8b2bc2 2489 xdg-dbus-proxy_0.1.8-1.dsc
 b6630bd24f8161b0e2546d2acbb014a3b3249f5c0d75f2a863ade898b9034d3d 45932 xdg-dbus-proxy_0.1.8.orig.tar.xz
 75a01f0fdd2b358e48ed313ab5362c52ca1bb49805fa07a95437c5be26f86154 4416 xdg-dbus-proxy_0.1.8-1.debian.tar.xz
 dfefbbd1a17925bc3cbacbf0fd4e165948116385ca0a056ae6490f3f020d38ba 110888 xdg-dbus-proxy_0.1.8-1.git.tar.xz
 d027f7fc496dedef3a849972b761fe4a20ed19c005dc870b7a38129974168a77 17580 xdg-dbus-proxy_0.1.8-1_source.buildinfo
Files:
 1558ae5bb8cf285df6c84309279b6d46 2489 admin optional xdg-dbus-proxy_0.1.8-1.dsc
 1a7b7a5f82653163495e82f7c9da7a36 45932 admin optional xdg-dbus-proxy_0.1.8.orig.tar.xz
 5b8bd9111953349bcc12c8db306e90a4 4416 admin optional xdg-dbus-proxy_0.1.8-1.debian.tar.xz
 8ea414b5d1871ba6decd64534c28f7aa 110888 admin optional xdg-dbus-proxy_0.1.8-1.git.tar.xz
 a97d8cafc5a31168b8636dfd3133d706 17580 admin optional xdg-dbus-proxy_0.1.8-1_source.buildinfo
Git-Tag-Info: tag=0940799236ea1e098f48ebb170cdc3a8acd3ee91 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp7HKoACgkQYG0ITkaD
wHlEYg/6AjpleeeS9c20sQVqqODhmJfIJ3QhESKjopUc3rNo+5cWvcc41Tq7SiJb
wB1jKmd18PkkY5Rsm3yMJkah5cAntBIHOelITsVBcTuS8IzxoG9ofY/0bFt4CqP7
9GQ3lHHTcJDv0mQlpGvuvrr1nJcD48HMUV9iue8VEjU44zuL6LGHBhTr7pEmg6+e
bdt9aigB3yHlzSzhpltuJQUzjC5Mk8qNRFnlL5czUHmhwvCCCth4+pAyINlmXfVs
eyP0dPEVywKKn0F73EUZdyiD2AhFuyoJ6rVaRG+jFSYjwR010UX3I7fhR36l3U2G
yGIavum/90Bm6MFgnprb9ikzFfwRSJISduV1WNDT5GsNduxsx3yLsRJ9xU8CRasz
x5Xw4YDAGVlBvNVVd2GolSfmwnYrJ/TyjwRJZJNt6vFcBYU7b1kA+JdiXUYYnU6d
fymmapcG99lc72oro2frsoIyG0hbT4CpHFpJqdbOEzvVYzLXrh9HnS/7zKksAVKb
YkWQ/c9sDDdvolzPrc0yfvItZV08Ru6P/St7qR+cKBW9ypoV2WBt5oQGvajVAfdm
833GMRNWG/jM2TMiuSjM96Z8SUGFDeNg77deLrwKSbaKdzGhKfKLnisvm82aFRnJ
od37GRoWaDfKEeXQ1+TOoK/si4/2tGZePU4h7nS8DGDAFYysNRs=
=//Jl
-----END PGP SIGNATURE-----

#1144129#15
Date:
2026-08-11 13:21:13 UTC
From:
To:
OK to upload?

Thanks,
     smcv

#1144129#20
Date:
2026-08-11 15:07:43 UTC
From:
To:
Sorry, I realised I uploaded this to security-master without permission
after receiving permission to upload flatpak. If this is a problem,
please reject it and I can do a fixed +deb13u3 as a followup or by a
different route.

     smcv