Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security update. Publication date: 07 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0178.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-34080 Description: A policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. References: - https://bugs.mageia.org/show_bug.cgi?id=35347 - https://www.openwall.com/lists/oss-security/2026/04/10/15 - https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677 - https://www.cve.org/CVERecord?id=CVE-2026-34080 SRPMS: - 9/core/xdg-dbus-proxy-0.1.7-1.mga9 . Mageia advisory MGASA-2026-0178 addresses an important xdg-dbus-proxy eavesdrop issue with critical fixes available.. Mageia Security Advisory, xdg-dbus-proxy Vulnerability, Mageia 9 Security Update. . Severity: Important. LinuxSecurity.com Team
It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6224-1
It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4542-1
It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6209-1
Get the latest Linux and open source security news straight to your inbox.