Project Subscriptions
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6510-1 | xdg-dbus-proxy security update |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail. |
| Title | xdg-dbus-proxy: xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape | xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Mon, 28 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flatpak
Flatpak xdg-dbus-proxy |
|
| Vendors & Products |
Flatpak
Flatpak xdg-dbus-proxy |
Mon, 28 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. | |
| Title | xdg-dbus-proxy: xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-02T16:51:40.902Z
Reserved: 2026-09-21T15:32:06.674Z
Link: CVE-2026-94422
Updated: 2026-10-02T14:12:15.134Z
Status : Awaiting Analysis
Published: 2026-10-02T14:17:12.003
Modified: 2026-10-02T18:44:11.270
Link: CVE-2026-94422
OpenCVE Enrichment
Updated: 2026-10-02T16:15:08Z
Debian DSA