xdg-dbus-proxy could be made to expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-8167-1 April 13, 2026 xdg-dbus-proxy vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: xdg-dbus-proxy could be made to expose sensitive information. Software Description: - xdg-dbus-proxy: A filtering proxy for D-Bus connections Details: It was discovered that xdg-dbus-proxy incorrectly handled eavesdropping in policy rules. A local attacker could possibly use this issue to intercept certain D-Bus messages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 xdg-dbus-proxy 0.1.6-1ubuntu0.1 Ubuntu 24.04 LTS xdg-dbus-proxy 0.1.5-1ubuntu0.2 Ubuntu 22.04 LTS xdg-dbus-proxy 0.1.3-1ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8167-1 CVE-2026-34080 Package Information: https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.6-1ubuntu0.1 https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.5-1ubuntu0.2 https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.3-1ubuntu0.1 . Ubuntu 25.10, 24.04 LTS, 22.04 LTS xdg-dbus-proxy exposes sensitive data - update recommended.. xdg-dbus-proxy, Ubuntu, sensitive information, local attack, security update. . Severity: Important. LinuxSecurity.com Team
This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error message in update --appdata when ther. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-bd651734da 2018-02-06 15:24:55.359844 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 27 Version : 0.10.3 Release : 1.fc27 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error message in update --appdata when ther was no updates * Fix handling of abort in the duplicate remote prompt * Fix division by zero in progress calculation * Fix flatpak remote-info --show-metadata --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade flatpak' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.