Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34080

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.

A flaw was found in xdg-dbus-proxy, a filtering proxy for D-Bus connections. A local client can exploit a policy parser vulnerability by crafting specific policy rules, such as including a space before the equals sign in "eavesdrop=true". This improper parsing allows the client to bypass intended eavesdrop restrictions. The consequence is information disclosure, where clients can intercept D-Bus messages that should otherwise be inaccessible.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10xdg-dbus-proxyFix deferred
Red Hat Enterprise Linux 9xdg-dbus-proxyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2456273xdg-dbus-proxy: xdg-dbus-proxy: Information disclosure due to policy parser vulnerability

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.

CVSS3: 5.5
nvd
4 месяца назад

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.

CVSS3: 5.5
debian
4 месяца назад

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0. ...

suse-cvrf
2 месяца назад

Security update for xdg-dbus-proxy

suse-cvrf
около 1 месяца назад

Security update for xdg-dbus-proxy

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3