Ubuntu alert USN-8167-1 (xdg-dbus-proxy)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8167-1] xdg-dbus-proxy vulnerability | |
| Date: | Mon, 13 Apr 2026 17:49:26 +0000 | |
| Message-ID: | <E1wCLPa-0008Ux-L0@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8167-1 April 13, 2026 xdg-dbus-proxy vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: xdg-dbus-proxy could be made to expose sensitive information. Software Description: - xdg-dbus-proxy: A filtering proxy for D-Bus connections Details: It was discovered that xdg-dbus-proxy incorrectly handled eavesdropping in policy rules. A local attacker could possibly use this issue to intercept certain D-Bus messages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 xdg-dbus-proxy 0.1.6-1ubuntu0.1 Ubuntu 24.04 LTS xdg-dbus-proxy 0.1.5-1ubuntu0.2 Ubuntu 22.04 LTS xdg-dbus-proxy 0.1.3-1ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8167-1 CVE-2026-34080 Package Information: https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.6... https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.5... https://launchpad.net/ubuntu/+source/xdg-dbus-proxy/0.1.3...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmndLJsACgkQcpJm3tlz hgFN1Q//dwRI2YrGynNPDnsn1XiHwK1QmlDMGF19MltP5elX3OrafjJapGUBUT8f HLhJ7xXl8bygsbSBXxiBVO9VsdUQo7p8kagcqfE5n9h7HvzuUQLOrZc4OBeL8A4i nyVk6YMJ3Uw8ikOro4ypfzhwYRtY6WDSVyYINREaBYNdT0CCwBddzU+Yha8hjJlF AoXv0Ypl5laa0IrWACNoh5qKKJ50CEAyiIxfZlfHKMXghJ62+5mbdu9kK9/mMxKc qx7zukR6NiTPnje81Dyo+nSSzEsMBNWkgK55hIqa0/X2RPdhWCj2toD/b9G6dhvU 03cSjPqWmN7dbbowp4yQqQM4O0xYbxA/Byvgmiqdl5rIVVbRrtwx37+vDaWkBAZJ 3u7wrvGjhhI5JQkaxCyVskKmZEIBJW0gfhE3izPiCId3Gqv+XyZ6wDnT1zz4RNvY vc4qcm50bokM+QN7O6aNtQSAM9SDAGTvvsFdawW7iD8fTH71ZcOSe06OpMe4xm0J aeg7Hfe4pg6UQjHPH3a5oCqZKXtNesLfU0SE1nGNwp/galOdp7WIz4pgxc5DLP/S efPhqXhQ9POOT4UcpktnQTo3//S7CcHjfdGbYUfTbV6e7TmieWRcM3phihTpX5Za sI2fIoXpco4UCgIuyJ7hXKi9OpuXBCtMJwdY3bDGFn0SOj0EVKc= =eVY+ -----END PGP SIGNATURE-----
