Back

HIGH

xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape

Published Oct 2, 2026

Description

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 2, 2026
Updated Oct 2, 2026
Reserved Sep 21, 2026
CISA Vulnrichment
Updated Oct 2, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a