-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 20:27:48 +0100 Source: xdg-dbus-proxy Binary: xdg-dbus-proxy xdg-dbus-proxy-dbgsym xdg-dbus-proxy-tests xdg-dbus-proxy-tests-dbgsym Architecture: amd64 Version: 0.1.4-3+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Simon McVittie Description: xdg-dbus-proxy - filtering D-Bus proxy xdg-dbus-proxy-tests - filtering D-Bus proxy - as-installed tests Closes: 1132939 Changes: xdg-dbus-proxy (0.1.4-3+deb12u1) bookworm-security; urgency=high . * d/gbp.conf: Configure for bookworm * d/p/Fix-GVariant-reference-leaks.patch: Add patch from upstream 0.1.6 fixing some memory leaks. As well as being a desirable bug fix, this is necessary for the fix for CVE-2026-34080 to apply cleanly. * d/p/flatpak-proxy-Use-g_autoptr-in-validate_arg0_match.patch, d/p/Improve-detection-of-eavesdrop-true.patch: Fix detection of eavesdrop=true match rules, resolving a vulnerability in which a malicious or compromised Flatpak app could monitor D-Bus traffic that it was not intended to be able to access. (CVE-2026-34080) (Closes: #1132939) Checksums-Sha1: 26d0d9d628ae6df1ab142ed63b385462018099b5 62136 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_amd64.deb 6ada9befd315649da4af6ba7d7d6459d0cbc28db 11440 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_amd64.deb 0aa18f3914baed92ad4219b7ab4236a0b6b58239 8156 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_amd64.deb 6a79beee21a59e9ddc1223bb842f6c434bb45951 8665 xdg-dbus-proxy_0.1.4-3+deb12u1_amd64-buildd.buildinfo b0021595c17db7322ce76e9232c9d1dfeb271030 23848 xdg-dbus-proxy_0.1.4-3+deb12u1_amd64.deb Checksums-Sha256: 2a2d1d5debf3991499d7ad85d8bb42b5abb29f7babbf6732822b32ad7e3a4a36 62136 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_amd64.deb f1fcb1868f0a1d600a34268e940f11d17ac205c3ab57879576f8e0523bd6ef17 11440 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_amd64.deb 96d0085bbcfc75eb8290867e196de668b45c2037926dbc681a0517bbd9111f6e 8156 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_amd64.deb 6a06f734af5dbcf7a23d9bcf293a1b6dca9ee3eeca1cb32bf8713850db5aaef8 8665 xdg-dbus-proxy_0.1.4-3+deb12u1_amd64-buildd.buildinfo 5b4c8488c0257859333dec4021498a1c3c7c6ff2bdaee4934edb8bf595528c48 23848 xdg-dbus-proxy_0.1.4-3+deb12u1_amd64.deb Files: 16711a9b93984659428c5ca972bb8a69 62136 debug optional xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_amd64.deb 4fcbdafe59cef1fc52511f46d02e7d47 11440 debug optional xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_amd64.deb 93250f0c5229c4acf48a98840027c90e 8156 admin optional xdg-dbus-proxy-tests_0.1.4-3+deb12u1_amd64.deb c9bd879550892a52adbec19ea67aab76 8665 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_amd64-buildd.buildinfo 24d77d201d975b586d92735d154326c7 23848 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmnnO8QACgkQTwt/65ON 6zcLFRAAgvv3iT5ERMikC1JPcHXySFeVRTOlutICAd7tJUVQLktsg5ui1RwMP6gd pkB0yxugreBACaasX11e+C9xrpdCo6fIj1r3jQCUrQMqzuY5PlsUIPPApZMG9s3x 8TAWrjGIoUjnJ6vZw1+vsehjwmcHUiCKexENtumg0Opaig/Y6KgVzHs7xiFSfMqC DQHnhKY3Edotb7UzZ8APebu86UO2IDOd0Caf+lhvGSGyuqoqp6J5JqjRmeQAk5Pf RlW6p/1qjgwIz8FvGQvgvsbV03sUTdVKa4qCmDwAmCvwhgwbVGJ4A1ugeYsgs51/ uqAaRVEsYinq+6n2HX4qtWakbAAUrFmp4MULYN9KzEep3+Ettk5nDcGnXajJcW20 vKGB1+/vmlXgw7o6FDNkBLnG656q+59dEd4onAEjCqbW3LaRZ2hye7SksSBBhXsN GxdiS+rXBedCU6VpzoKI/ocknSsqYrIVdalXWAXB4/j7CRSpvWiWakkgxPA95+IR SBhlTmsryYJruvfpO7isN7wgQqxGNjYFBZTdh4zZlFZCyd1MRUT3BxWkV0V3GMQ1 QBhJK2PhvoZ8wiaX4OgHV5oP5FP7TGi5yi1QhJnx3ebMor/qSrVr/qp1nz/BJbZT zxAibWaNgVYBECkHWq6uN9Di6OLORase1GyS057180eCkcQQarQ= =iHr+ -----END PGP SIGNATURE-----