ELA-1688-1 xdg-dbus-proxy security update

information disclosure

2026-04-21
Packagexdg-dbus-proxy
Version0.1.1-1+deb10u1 (buster)
Related CVEs CVE-2026-34080


It was discovered that incorrect parsing of policy rules in the xdg-dbus-proxy (a filtering proxy for D-Bus connections) allowed the bypass of eavesdrop restrictions, which could result in information disclosure.



For Debian 10 buster, these problems have been fixed in version 0.1.1-1+deb10u1.

We recommend that you upgrade your xdg-dbus-proxy packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.