-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 20:27:48 +0100 Source: xdg-dbus-proxy Binary: xdg-dbus-proxy xdg-dbus-proxy-dbgsym xdg-dbus-proxy-tests xdg-dbus-proxy-tests-dbgsym Architecture: armhf Version: 0.1.4-3+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Simon McVittie Description: xdg-dbus-proxy - filtering D-Bus proxy xdg-dbus-proxy-tests - filtering D-Bus proxy - as-installed tests Closes: 1132939 Changes: xdg-dbus-proxy (0.1.4-3+deb12u1) bookworm-security; urgency=high . * d/gbp.conf: Configure for bookworm * d/p/Fix-GVariant-reference-leaks.patch: Add patch from upstream 0.1.6 fixing some memory leaks. As well as being a desirable bug fix, this is necessary for the fix for CVE-2026-34080 to apply cleanly. * d/p/flatpak-proxy-Use-g_autoptr-in-validate_arg0_match.patch, d/p/Improve-detection-of-eavesdrop-true.patch: Fix detection of eavesdrop=true match rules, resolving a vulnerability in which a malicious or compromised Flatpak app could monitor D-Bus traffic that it was not intended to be able to access. (CVE-2026-34080) (Closes: #1132939) Checksums-Sha1: e5fbd476953f97f1d8b0da52e79d334aab8712f6 60272 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_armhf.deb ce908fec27f9bedc282ccbd16c737ca4c6b8dfcf 11536 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_armhf.deb 1d800da7181a2ef8a71eb5f83aaa7666a1bd575c 7520 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_armhf.deb 237b79687e7a785e2039549fbe0b26025726790b 8508 xdg-dbus-proxy_0.1.4-3+deb12u1_armhf-buildd.buildinfo 31936bc24e6652c912c80e07ab1f83f6ac5cbf73 21008 xdg-dbus-proxy_0.1.4-3+deb12u1_armhf.deb Checksums-Sha256: 27e9e3b39085d61cd00868332c3abca1c3deb5a6b5796158b29f0eeaca21aba0 60272 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_armhf.deb 11dcce0bdfcc1ca73e64f5a1583e2f6d1a50cfaa5935cbc6113b76aba1630fcc 11536 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_armhf.deb 6ed46497340f5df8ced738cb7c00a2dab93a45de2970e4f8ce3bdcc7c45fa871 7520 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_armhf.deb 545fcab3d770b9d23066c630d591dd54afbfebca9120eb7ac450e1c9124a5a01 8508 xdg-dbus-proxy_0.1.4-3+deb12u1_armhf-buildd.buildinfo 777d0e4671d8fa123ea95cde6227ec8c51d3a22b981ca3d6dd046ea4da81ab3b 21008 xdg-dbus-proxy_0.1.4-3+deb12u1_armhf.deb Files: fc734e80b69d56b094e00bd1253e9ba9 60272 debug optional xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_armhf.deb e39eac4a592316b33632ce9cc8058970 11536 debug optional xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_armhf.deb 91f1dd40475e78544dc97b24e22cc6da 7520 admin optional xdg-dbus-proxy-tests_0.1.4-3+deb12u1_armhf.deb 1d5709142bf22cb1ad184eca5a0850ac 8508 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_armhf-buildd.buildinfo 506d39ab6a44fb8b4007f54811f38464 21008 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmnnOl4ACgkQLRECdjCZ QkeW8A/+Jvb3bewiRcNfIO0SQpS42AJJ5Kb7171Z6Ygo5UyTr31mEgh5gKnZojJM IqRox6p7sG67zbiZYUAMUsKkyW/fRT30Ne3j1kfUDykMfN+63XzSukV6aabBtHj0 fIXrOmwngFekufvuOfCFCqxOj42LtDO0kUf3P1iq3FMsYNtPF/E79vHBNtmHcTqs 5A33lSk0fOo6NTrFo+Ad98OxpEu1j9iUcrYXsrl5yYVtLWkk7iXKciiWOV03r1mZ lPSUQj+4jeacmcjG6olpcP+Iv9ORCf91TIMX/Vce+Dqml0dc0dkIDRmndLh6zofP JGawDHvsK2hcUoPRdB6FuRISefOwMPyc8GMt+hOt52VfrVPVKVeaPKLN6hI0YeYq OCPWOjzCvbaExn7DIYT3lo4vU7z+OqMW7+da5eCz635sAYhhKWeV1IPvHXadGyiW 7ixDkUHDCWRdBLBl00gbarPRr2QRnxctnnaFyJBbhE+9bknOvPtxup8MYQyONJuj u25ZbmH+02oIt5SEwWOUw+EX6M2bfc2vJHcOJ4FvUn0eaQsCpwOMP6BhkCdBLfgc VZIJ5x6Vxx1v9u7ITJ//M8Sl59E8XuYnLo5CY+Co9lCXrbDnElpEhP4g+4y9g7lX 5pWBDk18CdYLKJ4ui1sxmmC4Kf89aw6dkl+leOsy06LhL7c504U= =bHq3 -----END PGP SIGNATURE-----