Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 9 xdg-dbus-proxy Serious Eavesdropping Vulnerability MGASA-2026-0178

Security update. Publication date: 07 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0178.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-34080 Description: A policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. References: - https://bugs.mageia.org/show_bug.cgi?id=35347 - https://www.openwall.com/lists/oss-security/2026/04/10/15 - https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677 - https://www.cve.org/CVERecord?id=CVE-2026-34080 SRPMS: - 9/core/xdg-dbus-proxy-0.1.7-1.mga9 . Mageia advisory MGASA-2026-0178 addresses an important xdg-dbus-proxy eavesdrop issue with critical fixes available.. Mageia Security Advisory, xdg-dbus-proxy Vulnerability, Mageia 9 Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 07, 2026 Important Mageia
87

Debian xdg-dbus-proxy Important Eavesdrop Bypass CVE-2026-34080 DSA-6224-1

It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the oldstable distribution (bookworm), this problem has been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6224-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xdg-dbus-proxy CVE ID : CVE-2026-34080 It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 0.1.4-3+deb12u1. We recommend that you upgrade your xdg-dbus-proxy packages. For the detailed security status of xdg-dbus-proxy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xdg-dbus-proxy Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Eavesdrop restriction bypass vulnerability in xdg-dbus-proxy fixed. Upgrade your Debian package to ensure security.. Debian Security, xdg-dbus-proxy, D-Bus connections, information disclosure, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 22, 2026 Important Debian
197

Debian 11 bullseye xdg-dbus-proxy Moderate Info Leak DLA-4542-1

It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4542-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort April 21, 2026 https://wiki.debian.org/LTS Package : xdg-dbus-proxy Version : 0.1.2-2+deb11u1 CVE ID : CVE-2026-34080 Debian Bug : 1132939 It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For Debian 11 bullseye, this problem has been fixed in version 0.1.2-2+deb11u1. We recommend that you upgrade your xdg-dbus-proxy packages. For the detailed security status of xdg-dbus-proxy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xdg-dbus-proxy Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The xdg-dbus-proxy for Debian had a parsing issue that led to information disclosure; upgrade to fix it now.. Debian, D-Bus, security advisory, information disclosure, xdg-dbus-proxy. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Debian LTS
87

Debian xdg-dbus-proxy Critical Info Disclosure Vuln DSA-6209-1

It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6209-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 13, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xdg-dbus-proxy CVE ID : CVE-2026-34080 It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure. For the stable distribution (trixie), this problem has been fixed in version 0.1.6-1+deb13u1. We recommend that you upgrade your xdg-dbus-proxy packages. For the detailed security status of xdg-dbus-proxy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xdg-dbus-proxy Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Incorrect parsing in xdg-dbus-proxy exposes information disclosure risk. Upgrade recommended for Debian trixie users.. xdg dbus critical advisory security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200