{"id":"AZL-105923","summary":"CVE-2026-94422 affecting package xdg-dbus-proxy 0.1.6-2","details":"An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.","modified":"2026-10-03T14:16:36.331917985Z","published":"2026-10-02T14:17:12Z","upstream":["CVE-2026-94422"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94422"}],"affected":[{"package":{"name":"xdg-dbus-proxy","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/xdg-dbus-proxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.1.6-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105923.json"}}],"schema_version":"1.9.0"}