Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94422— xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape

Quick assessment

Affected
CVE-2026-94422
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 xdg-dbus-proxy 0.1.9 版本之前,消息过滤机制存在错误实现,攻击者可以通过在非回复消息中设置回复序列号(reply serial number),绕过 D-Bus 会话总线上的预期消息过滤。恶意或已被攻陷的 Flatpak 应用可能利用此漏洞,在沙箱之外执行任意代码。xdg-dbus-proxy 原本旨在作为 Flatpak 沙箱边界的一部分,但该项目以独立形式发布,有时也被其他应用框架(如 Firejail)所使用。

CVSS 8.8 · High

Possible ATT&CK Techniques 2 AI

T1453 T1055 · Process Injection

I. Basic Information for CVE-2026-94422

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
Source: CVE Program / CVE List V5
Vulnerability Description
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 0.1.9 -
Fedora Fedora 0 ~ 0.1.9 -
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10

II. Public POCs for CVE-2026-94422

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94422

请登录查看更多情报信息。

Other References for CVE-2026-94422 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-94422

No comments yet


Leave a comment