[BLFS Trac] #23734: xdg-dbus-proxy-0.1.8

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23734: xdg-dbus-proxy-0.1.8
-------------------------+------------------------
 Reporter:  Joe Locash   |      Owner:  Joe Locash
     Type:  enhancement  |     Status:  assigned
 Priority:  elevated     |  Milestone:  13.1
Component:  BOOK         |    Version:  git
 Severity:  normal       |   Keywords:
-------------------------+------------------------
 From https://www.openwall.com/lists/oss-security/2026/08/11/10:

 {{{
 Message-ID: <[email protected]>
 Date: Tue, 11 Aug 2026 17:52:36 +0100
 From: Simon McVittie <[email protected]>
 To: [email protected]
 Subject: xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast
  message filtering bypass

 https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-
 698j-2h6c

 xdg-dbus-proxy is a filtering proxy for D-Bus messages, used by Flatpak
 and perhaps other sandboxing frameworks (for example Firejail seems to
 contain references to it).

 xdg-dbus-proxy versions 0.1.6 and 0.1.7 had an incorrect implementation
 of broadcast message filtering, which allowed sandboxed apps to receive
 more broadcast messages than the configured filter rules allow. In
 Flatpak, this typically affects the D-Bus session bus (user bus) used by
 user applications, and the AT-SPI bus used by accessibility tools.

 A CVE ID has been requested, but is not yet available: please
 cross-reference this vulnerability as GHSA-r7hp-698j-2h6c until a CVE ID
 becomes available.

 This is fixed in 0.1.8, or can be patched in older versions by reverting
 commit 029784535ed9cbec6c431b12ba1a9eca6c147055 "Don't require TALK
 permission for broadcast rules". Versions 0.1.5 or older are not
 vulnerable.

 Note that fixing this vulnerability may cause regressions unless app
 frameworks are updated appropriately: see the full advisory for details.
 In Flatpak, this regression was avoided by commit 2afb4cf "run-dbus:
 Correct --broadcast rules for the AT-SPI bus", which was included in the
 1.18.1 and 1.19.0 releases. Other sandboxing frameworks might need a
 similar change.
 }}}

 Changes:

 {{{
 Changes in 0.1.8
 ================

 Released 2026-08-11

   * Fix broadcast messages bypassing path/interface/member checks
   * Improvements to the existing testing infrastructure
   * Add tests for owning names, issuing method calls, receiving messages
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23734>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.