PT-2026-102983 · Firejail+2 · Firejail+2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xdg-dbus-proxy versions prior to 0.1.9
Description
An incorrect implementation of message filtering allows an attacker to bypass intended filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could exploit this to achieve arbitrary code execution outside its sandbox. This component is intended to be part of the sandbox boundary for Flatpak and is also utilized by other frameworks such as Firejail.
Recommendations
Update to version 0.1.9 or later.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firejail
Flatpak
Xdg-Dbus-Proxy