-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 20:27:48 +0100 Source: xdg-dbus-proxy Binary: xdg-dbus-proxy xdg-dbus-proxy-dbgsym xdg-dbus-proxy-tests xdg-dbus-proxy-tests-dbgsym Architecture: i386 Version: 0.1.4-3+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Simon McVittie Description: xdg-dbus-proxy - filtering D-Bus proxy xdg-dbus-proxy-tests - filtering D-Bus proxy - as-installed tests Closes: 1132939 Changes: xdg-dbus-proxy (0.1.4-3+deb12u1) bookworm-security; urgency=high . * d/gbp.conf: Configure for bookworm * d/p/Fix-GVariant-reference-leaks.patch: Add patch from upstream 0.1.6 fixing some memory leaks. As well as being a desirable bug fix, this is necessary for the fix for CVE-2026-34080 to apply cleanly. * d/p/flatpak-proxy-Use-g_autoptr-in-validate_arg0_match.patch, d/p/Improve-detection-of-eavesdrop-true.patch: Fix detection of eavesdrop=true match rules, resolving a vulnerability in which a malicious or compromised Flatpak app could monitor D-Bus traffic that it was not intended to be able to access. (CVE-2026-34080) (Closes: #1132939) Checksums-Sha1: 9f2c0c83bef943e70c971673495de19181270f7b 57928 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_i386.deb 86fb0ae437016233a16ae3c5640c02f691f6a704 10500 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_i386.deb 6771f155368c8485fa1961b15f1ea2fff8d3dc14 8232 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_i386.deb 83e0993c2c810ecabce323b66a87081f6d2b8adb 8583 xdg-dbus-proxy_0.1.4-3+deb12u1_i386-buildd.buildinfo 16b169dad6d857537e33d65ed618931c8a0b2841 26124 xdg-dbus-proxy_0.1.4-3+deb12u1_i386.deb Checksums-Sha256: e7adedac07d634ec6b584975dac579c6304845635306c86338712b71f40e08e0 57928 xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_i386.deb 670b19c05c999206e21d424f34a354854a7f52cefccce8461f34b2ed174e3e6d 10500 xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_i386.deb d2ef0b3aa85f524adcc1152d121845059bd25d10037c9e58cb931bec355d30fb 8232 xdg-dbus-proxy-tests_0.1.4-3+deb12u1_i386.deb 8e1af1320405790348c3cf9870ee2d722e7983278421bd6f030cd1ebd3396074 8583 xdg-dbus-proxy_0.1.4-3+deb12u1_i386-buildd.buildinfo b26dfd58358bf6fa3938281b1cba60f52a41fe7b77b10a1a87fc5490ab872b55 26124 xdg-dbus-proxy_0.1.4-3+deb12u1_i386.deb Files: a2ca2156fcd60ccb372b1cd566ee27b4 57928 debug optional xdg-dbus-proxy-dbgsym_0.1.4-3+deb12u1_i386.deb ecc6ab5bbeb908a55dab24e14f827fd9 10500 debug optional xdg-dbus-proxy-tests-dbgsym_0.1.4-3+deb12u1_i386.deb 3b0e94b3a37ae0ee60b608607198c798 8232 admin optional xdg-dbus-proxy-tests_0.1.4-3+deb12u1_i386.deb a3e5adec28e3f7f5bfddaeab265ca561 8583 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_i386-buildd.buildinfo 176b1a03171c0a63e550502e0bf4eff5 26124 admin optional xdg-dbus-proxy_0.1.4-3+deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmnnPFIACgkQTwt/65ON 6zcemA//dMl2SPR6d1wSP/BxEorbNv1fin8swmXEjjTPb59VlGOLH5cUNOepdJWK e5Gwk+Y1UERrbcjDZJfRz+a/rBSlwNWHN4t2Sw0uootKS2YMsqe38uc6r2ICzOBh fl39DmA2uk7s/aCegTtSqD9QPwNk1hLtsgNvfMPQ04J4KCr3Jgoy5vvQ7lGGsMM4 ZvxUtCm3x7ChNOUenvhxOVHC88kepyJb2SAD7kSGzvvk6q/pDyULDW7XZBPP54Hk WEdiVApQoLA/A7F3lFfgRFeZdJGAVQrhyd6+OomGf6XdyzvdCrDyB3ygKG3vij+T A/ixH+JcY37UXlslffLArLXQ4T+jT0Sp0M7qagELg6InabzwYkPZQZNypsDPIBIq JMg4RGmOh7tT+NQ727X71FSNxjso3kY/69slI+af5E8bIbdjAi2ZOE+G/6EkIWP/ 0MAPgFVwKTUqzo7E6zuHhMgkPM74zt4TpRHyo1/LDbAEtnMnsrdvFoc8YbjhORcR huBxJ+SJPQ0XRzgFElW3++uc6dUEQY/Ca0q0C9ZPg0K3aBPYLWVxgla70FOVv3r8 1YZQrO/la1j7yf4JWZtjMVt/O0kbaNWbmsKA/+6la2g+s/bhfBveq+Tlanmm1rlh rsIskLjOli1WjRd/h9eEtaRtvpdyVrIxDgVr7DvKocAoVjmC/zo= =B2ZM -----END PGP SIGNATURE-----