{"id":"CVE-2026-94422","summary":"xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape","details":"An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.","aliases":["GHSA-2cgv-pwcq-wvpq"],"modified":"2026-10-04T07:04:16.409663088Z","published":"2026-10-02T13:54:10.589Z","related":["openSUSE-SU-2026:11913-1"],"database_specific":{"cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94422.json","cna_assigner":"redhat"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/09/23/5"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://bodhi.fedoraproject.org/updates/?packages=xdg-dbus-proxy"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-94422"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94422.json"},{"type":"ADVISORY","url":"https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94422"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2542235"},{"type":"FIX","url":"https://github.com/flatpak/xdg-dbus-proxy/commit/e4465a0dfe96da3b39929a30a1ac3a22b16223e3"},{"type":"FIX","url":"https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400"},{"type":"FIX","url":"https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e"},{"type":"PACKAGE","url":"https://github.com/flatpak/xdg-dbus-proxy"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/flatpak/xdg-dbus-proxy","events":[{"introduced":"0"},{"fixed":"72b40c8f6d9d585cfbdb249690724f740d207087"},{"fixed":"e4465a0dfe96da3b39929a30a1ac3a22b16223e3"},{"fixed":"e5702fca4dba9600721921fbca2dbc39dc5ca400"},{"fixed":"fc027f759316fb2a6c45648200b6f100202eb84e"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.1.9"}]}}],"versions":["0.1.8","0.1.7","0.1.6","0.1.5","0.1.4","0.1.3","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-94422.json","vanir_signatures":[{"target":{"file":"flatpak-proxy.c","function":"got_buffer_from_client"},"deprecated":false,"digest":{"function_hash":"60660592306273335752409373049810668455","length":3397},"id":"CVE-2026-94422-073b373a","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e"},{"id":"CVE-2026-94422-195bf6ae","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e","target":{"file":"flatpak-proxy.c"},"deprecated":false,"digest":{"line_hashes":["127539200921787682095583116955048507997","332100610272335632486078497141716361612","6700531888899798426445757426789780200","253611905278887520813879105681107761714","66326802731086662739391650264021877159","203547533127986499755695108548421989642","173878156555487118740790950504304142821","72607511093265852538802829288550278408","255369318311551611832130130115971717103","234950232295825103952543303366657387666","191594920815313139047230507698679405325","89236190513765718229926031721812857634","78885303237091880251844288951396701071","162377607880190927996299896594279274683","153097836638774622698701779208640322125","109499140629255621968514331803138186944","36343974437754435911145033008200848590","291670559291412677953097784851269692437","184195162397993807452449163462755928604","283675478126445828330537920266710601656","56579013132095059668629420333048494362","13066552145364567275314690033476034334","144593429879208132141932007613426188261","72667902760769147735618047765273885700","328858870428537403934819330637353316946","36343974437754435911145033008200848590","214328395007845213153302169550437307346","39590430747443549632029785541588456526","267079884385098371121658411912461171867","189821931812477011723368049963427534914","24973021427930984446979609626331740697","148093249091589822978103547666867178421","273246106891019011842451995302608976776","130103912618840197192245861578698736989","45657012836026740984448469688629785637","226312517612399753459625835971623364194","162367916703401801113327842203873145266","204594058141178765313071205823721300184","105626370749277828957161790917715460871","296204015861468364092617383360127527403","184195162397993807452449163462755928604","333599121106586303863684060248618260025","139183517527597895390710638332151616134","231049018839240130799841593246626134156","320863099075017064562969856814951091332","195171263728043520617484904845240408815","267911668632076480716483795408484684136","65583582638000410667695100867836150706","331396428275677447228085185347963910853","251377243768657292255714155498796626082","172990045900844078287461692870385081999"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400","target":{"file":"flatpak-proxy.c","function":"got_buffer_from_bus"},"deprecated":false,"digest":{"function_hash":"109805863521917563826914666317457881342","length":3623},"id":"CVE-2026-94422-3c23b69b","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"101886033121010108326922321989018429655","length":2122},"id":"CVE-2026-94422-46a75169","signature_type":"Function","signature_version":"v1","source":"https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400","target":{"function":"get_dbus_method_handler","file":"flatpak-proxy.c"}},{"source":"https://github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e","target":{"file":"flatpak-proxy.c","function":"got_buffer_from_bus"},"deprecated":false,"digest":{"function_hash":"42334481138916073535633900961722314063","length":3525},"id":"CVE-2026-94422-97340f16","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["161510921744665660011110131505958765919","169950437354264837268206341744971402498","21253125146561433354054923095803453096","229379547655925355036584961254924473813","285491442697780022592429720736122878582","27158866836501713194621641918615046383","101595509793839130390119183374634225647","289381548351604397323296302323074572506","9383428098537989184172799737545375791","80698571986437320140293418531212561256","332348436558542724717483435575215664393","201461655534259133828988858197031959235","105230699018747422717390319955010389697","230709243045989922431529580240308076493","331271999155406620942816151212804619760","331545200724569375085762971668910947873","269275105305036851749160008245174890934","156771980021063722265761819615052065328","174917393057218943205582414619906520633","11984688680834104161164307169976420205","254718535428122208431232024754615296186","77067326260305456034895653182566599750","115730607234936392619719305526343660129","210017202377675426419243600451875854078","220069536832095029360184279935186203410","60178695773917764994422458997261993194","168962695273515533069748375988865711421","213533614998213741965697321194324224984","260927693142078964459331661371742950366","309870042621213765021603500939918362428","90453927810853749735998885187507182635","106926624660553613862398748339192343420","150893312050162918820883594375184748019","41111049813249115237900935908142872574","270499705609695720731275858513054984714","87873302132317711410697368012881268527","329423545619469730157639615111133686908","229997718237548964922260735415759494929","168784812697584322269191635502236849450","95171117406024190483781845030019660400","174343192250848999346766289166653183380","10713075615237734227420048022423960160","218664771391060894725708941959170320310","311469948914192732410919998651127354712"]},"id":"CVE-2026-94422-a0108a9a","signature_type":"Line","signature_version":"v1","source":"https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400","target":{"file":"flatpak-proxy.c"}},{"source":"https://github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400","target":{"function":"parse_header","file":"flatpak-proxy.c"},"deprecated":false,"digest":{"length":8662,"function_hash":"236587940773964875336337486251649246506"},"id":"CVE-2026-94422-acdf3ff8","signature_type":"Function","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-04T07:04:16Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}