#1148782 xdg-dbus-proxy: CVE-2026-94422: Message filtering bypass via reply serial (GHSA-2cgv-pwcq-wvpq) #1148782
- Package:
- xdg-dbus-proxy
- Source:
- xdg-dbus-proxy
- Description:
- filtering D-Bus proxy
- Submitter:
- Simon McVittie
- Date:
- 2026-10-02 15:27:03 UTC
- Severity:
- normal
- Tags:
Control: tags -1 + pending https://salsa.debian.org/debian/xdg-dbus-proxy/-/commits/debian/trixie-proposed Source and binary test-build (functionally equivalent to what I propose, only differs in the changelog): https://people.debian.org/~smcv/temp/2026/CVE-2026-94422/ If the LTS team looks at this: the changes might well apply cleanly to older x-d-p versions, but I haven't tried. Or backporting a whole newer x-d-p would also be reasonable - basically the whole thing is security-sensitive, so you won't gain much by isolating security fixes. smcv
We believe that the bug you reported is fixed in the latest version of
xdg-dbus-proxy, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148782@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated xdg-dbus-proxy package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 15:07:42 +0100
Source: xdg-dbus-proxy
Architecture: source
Version: 0.1.9-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1148782
Changes:
xdg-dbus-proxy (0.1.9-1) unstable; urgency=high
.
* New upstream release
- Fix message filtering bypass vulnerabilities
(CVE-2026-94422, GHSA-2cgv-pwcq-wvpq, Closes: #1148782)
* Mention CVE-2026-93676 in previous changelog entry
* d/patches/series: Remove empty patch series
Checksums-Sha1:
32cc44c2caf63c3eec67a869c791d486c1b83786 2489 xdg-dbus-proxy_0.1.9-1.dsc
ff6c4973cb7037b4bbb0004cc342f9fc762c0831 48716 xdg-dbus-proxy_0.1.9.orig.tar.xz
780d27e8a0a1733605ce07d6eb8dfc56fe7e3268 4456 xdg-dbus-proxy_0.1.9-1.debian.tar.xz
3cbfbb9e1efaecb31b6e4c3b0283df470d22556b 119720 xdg-dbus-proxy_0.1.9-1.git.tar.xz
4a89f3cc3db65e48f245cc729b816ed9615c4bc3 17750 xdg-dbus-proxy_0.1.9-1_source.buildinfo
Checksums-Sha256:
cd6cdb54e1eceb8ff7bfe11da53c83eb2a83662deb3e82d1c65355cbed74f264 2489 xdg-dbus-proxy_0.1.9-1.dsc
5450dda586ec3bb3ca709d311e845487883faa3b09cf562608d7e84f4311dced 48716 xdg-dbus-proxy_0.1.9.orig.tar.xz
6f4945c422ef35ff2c504c3963bfb79a6effc086657f0c87e46987f7ca7354d3 4456 xdg-dbus-proxy_0.1.9-1.debian.tar.xz
bc228dcaf0025731100fc249cdf3640c6353ccb24cf1fafb9a9b105223cd7ce7 119720 xdg-dbus-proxy_0.1.9-1.git.tar.xz
6a220d7bcdb7296b356b31af506eef12cc9fdde4a805af4c6209de5907c4d457 17750 xdg-dbus-proxy_0.1.9-1_source.buildinfo
Files:
c78c0d3cc41d1af57d60468259cb064e 2489 admin optional xdg-dbus-proxy_0.1.9-1.dsc
ce99fa3fe140e817d70be0fd45b3a2a3 48716 admin optional xdg-dbus-proxy_0.1.9.orig.tar.xz
76f33b9c87bf2db44200dc85b9db6c7b 4456 admin optional xdg-dbus-proxy_0.1.9-1.debian.tar.xz
0fe09ef94e2d844bdb66161532fb5c1b 119720 admin optional xdg-dbus-proxy_0.1.9-1.git.tar.xz
b7510b089579eb820a68c0e2e065db63 17750 admin optional xdg-dbus-proxy_0.1.9-1_source.buildinfo
Git-Tag-Info: tag=a154a86755ca45c00b38c53194f13d4f72bd74c7 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqz4l8ACgkQYG0ITkaD
wHnyzxAA1RvPym3J7k2UNY0vmmnUBxgqQcXulaB7YZB6HQUGW8hLgkVCV0NYrt7X
810S58KRAWfuO/RqPZET4Jie8avXVk1IvG8lVuUjUMnCvqj9OIuotm8vXJvVjOqm
ZZiyAd8OlF1W4oQ2+dg058QiPw11vCQljm/YEMhlYHcsrrU2yrJ3QFEFRuAutYgL
cqhKgmf+bce1+du1DV8NMNAPtICL1Im49y5JX25IzWUc6wUQMdC8c+yByP1Y9oYw
iiWYcKw5FCCiwOoBq0udAegEVJwqAjEU/ZSPcKRltyNknVfRxLZIOqpUBDK75m3s
yKgf96ucs8x1ehQ4masf/rt/QqtKUabZa2xoITdXqQSyy0zz1wX8MhR/ktpanlzG
znekQVaardZ1PmudeFNte8O/u+C9xbk17DaD6svbo+qdj7OgKYdoNtOQeK05gSc9
v/1dvg6h0yHi+se7dbTnFly/Fug2ygIojLZdj1TEBHd+mMPgF+NMUkc+xNJliB3n
JWA7MUPqBSkCX2E+6CHL2YnQ1lLMvS3myJQ7ymiwfq91zCp4lHIY6SzF5+eM8fKh
25xbrWvqIuFDoty85j9Gzro/n8Wft+SwI1QGCIXYF4JYMku9E2sIRTF7axtwJJNE
9fSrkbgi8mXHEDrdSVYfzmJee7Nc4gtxLqWl0jtywWwHGon2eNU=
=kyaz
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
xdg-dbus-proxy, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148782@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated xdg-dbus-proxy package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 13:16:29 +0100
Source: xdg-dbus-proxy
Architecture: source
Version: 0.1.6-1+deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1148782
Changes:
xdg-dbus-proxy (0.1.6-1+deb13u3) trixie-security; urgency=high
.
* d/p/CVE-2026-94422/*.patch:
Apply patches from upstream release 0.1.9 to fix message filtering
bypass vulnerabilities.
A malicious or compromised Flatpak app could use these vulnerabilities
to escape the sandbox and execute arbitrary code on the host.
(CVE-2026-94422, GHSA-2cgv-pwcq-wvpq, Closes: #1148782)
* Mention CVE-2026-93676, #1144129 in previous changelog entry
Checksums-Sha1:
49ef3c4a3eecc3750cf058ded6cafd0d59cf7302 2232 xdg-dbus-proxy_0.1.6-1+deb13u3.dsc
4c07aa2693bb12d6f5cb32b5e8693c98b53725e7 20724 xdg-dbus-proxy_0.1.6-1+deb13u3.debian.tar.xz
f6dbc1a39474f6121bda0d872698158493b189da 7943 xdg-dbus-proxy_0.1.6-1+deb13u3_source.buildinfo
Checksums-Sha256:
ab440e81165d397918024961c4b20ba58bb9e7d263554d1de8cbb54f9cd46b86 2232 xdg-dbus-proxy_0.1.6-1+deb13u3.dsc
ca9cd0cde2b2d6371d5120dd74cfbf30f755875a3a084bfb466748ef56594e32 20724 xdg-dbus-proxy_0.1.6-1+deb13u3.debian.tar.xz
bd81c95c214be8a3c42f8e303c4df9edb58a0b6dc3dc4df405df79371f76cf6f 7943 xdg-dbus-proxy_0.1.6-1+deb13u3_source.buildinfo
Files:
ea3d428b78b291ef041d05b81b78c0e7 2232 admin optional xdg-dbus-proxy_0.1.6-1+deb13u3.dsc
8748a0847cbaad3849be735856d73ec1 20724 admin optional xdg-dbus-proxy_0.1.6-1+deb13u3.debian.tar.xz
8ab55748162f3d2ae0bd0e938ec2b102 7943 admin optional xdg-dbus-proxy_0.1.6-1+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmqz5zIACgkQI1wJnT6z
MHaEYA//ZB1nJgDdZweQ73k+fYZKXq4VbO2EguSfZbeOtEZpZR7ZSlbvZxdZCeNg
n1eAY8+IVfGWCXRM2B/38K1rJT/eF4gFflnM+mNOjyX0wZBNb5TukEVKaya+qLbz
waOuR+7ankH/DOj18A39S7bq2fl4j2dVgD4qSCkOiS42DxUIZDAXDoI+rURttbe9
VwPRWa/OxP4Pg5jAn/hPURYrA5KiUABvbUZ72ptcyRJOFG/ZBx6Oc83DLHzhrxbu
iNA5Jd/3eRqzCwJGTrttP8FGlA47FE3Jfs+ZbqCISd4Ur68al8vZ5o5jtL5GKeaD
pwrkoA7BIH6IcRfR6az88Y4Ev9It9qFnLwoa3vV5inLPo6+DgLvw+WJFA0oaHync
HiTWiGdOI8lYeltIpAcfiT5wYF2FA9iAfSLG6Abpw+fE2DgPkMztF6oRD+MC+9DV
6NjZgeg+WNZsqiRaNtBdl/sflgOLZK1fZQJDQ08rmRG+wx56pfZcqZtWVjnYGqC+
3MnyS/tmhoOBiuPYJf7eaeOeRlI4mQBfIdMDDp0F6Mnwwpzd+Q3nnuah8LlU3z+j
IHVPJMVUrLgLCgXgFG+3afhk7pNsMUFXzRvGyktSe+digWsDwPQubRWofXabOK/w
1B+f6vKmQ1SZVZJH2E2VrbLxlrxpVD37TsCjmFeJ3mzuqpeXlSY=
=sko/
-----END PGP SIGNATURE-----