Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-94422: xdg-dbus-proxy lets sandboxed apps escape
CVE-2026-94422 · published today
Summary
The xdg-dbus-proxy component used in Debian, Ubuntu, Fedora and Red Hat Enterprise Linux 9/10 can be tricked into passing messages it should block, allowing a compromised Flatpak or similar app to run code outside its sandbox. This risk exists in all versions before 0.1.9. Update xdg-dbus-proxy to version 0.1.9 or later to close the gap.
What to do
- Update debian xdg-dbus-proxy to version 0.1.6-1+deb13u3.
- Update debian xdg-dbus-proxy to version 0.1.9-1.
- Update fedora fedora to version 0.1.9 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | xdg-dbus-proxy | All versions |
| Debian:13 | debian | xdg-dbus-proxy |
< 0.1.6-1+deb13u3 Fix: upgrade to 0.1.6-1+deb13u3
|
| Debian:14 | debian | xdg-dbus-proxy |
< 0.1.9-1 Fix: upgrade to 0.1.9-1
|
| Ubuntu:Pro:20.04:LTS | canonical | xdg-dbus-proxy | All versions |
| – | fedora | fedora | < 0.1.9 |
| – | red hat | red hat enterprise linux 9 | All versions |
| – | red hat | red hat enterprise linux 10 | All versions |
Original advisory text
xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
References
- https://security-tracker.debian.org/tracker/CVE-2026-94422 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-94422 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-94422 Third Party Advisory
- https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvp... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-94422 Vendor Advisory
- https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc3... Patch
- https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f10... Patch
- https://github.com/flatpak/xdg-dbus-proxy/commit/e4465a0dfe96da3b39929a30a1ac3a2... Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=2542235 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/09/23/5 URL
- https://github.com/flatpak/xdg-dbus-proxy Product
- https://access.redhat.com/downloads/content/package-browser/ URL
- https://bodhi.fedoraproject.org/updates/?packages=xdg-dbus-proxy URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94422... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-94422 Vendor Advisory
Severity
9.9
Critical
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published2 Oct 2026
Updated3 Oct 2026
First seen23 Sep 2026
Sources
DEBIAN-CVE-2026-94422 · OSV
UBUNTU-CVE-2026-94422 · OSV
CVE-2026-94422 · NVD
CVE-2026-94422 · MITRE
CVE-2026-94422 · OSV
GHSA-2cgv-pwcq-wvpq · GHSA
Track software like this
Free during beta