Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Mageia 9 xdg-dbus-proxy Serious Eavesdropping Vulnerability MGASA-2026-0178

mageia
Calendar Grey June 7, 2026
Dist Mageia Esm H88
Mageia advisory MGASA-2026-0178 addresses an important xdg-dbus-proxy eavesdrop issue with critical fixes available.
Security update

Summary

Description: A policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases.

References

- https://bugs.mageia.org/show_bug.cgi?id=35347

- https://www.openwall.com/lists/oss-security/2026/04/10/15

- https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677

- https://www.cve.org/CVERecord?id=CVE-2026-34080

Resolution


Warning: Undefined array key "block" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4047326_e054056aed0948774f0d9dcb331a22bc on line 17

Warning: Undefined array key "block" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4047326_e054056aed0948774f0d9dcb331a22bc on line 21

Warning: foreach() argument must be of type array|object, null given in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/4047326_e054056aed0948774f0d9dcb331a22bc on line 21

SRPMS

- 9/core/xdg-dbus-proxy-0.1.7-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 07 Jun 2026 
URL: https://advisories.mageia.org/MGASA-2026-0178.html
Type: security
CVE: CVE-2026-34080

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here