Improper Validation of Unsafe Equivalence in Input in xdg-dbus-proxy - CVE-2026-34080

 

Improper Validation of Unsafe Equivalence in Input in xdg-dbus-proxy - CVE-2026-34080

Published: April 10, 2026


Vulnerability identifier: #VU125785
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34080
CWE-ID: CWE-1289
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a policy parser issue. A remote attacker can bypass eavesdrop restrictions and intercept D-Bus messages.


Affected software

xdg-dbus-proxy
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
xdg-dbus-proxy (Ubuntu package)
xdg-dbus-proxy-debugsource
xdg-dbus-proxy-debuginfo
xdg-dbus-proxy
xdg-dbus-proxy-help
xdg-dbus-proxy (Debian package)

How to mitigate CVE-2026-34080

Install updates from vendor's website.

xdg-dbus-proxy - update to 0.1.7
xdg-dbus-proxy (Ubuntu package) - addressed in versions 0.1.2-1ubuntu0.1~esm1, 0.1.3-1ubuntu0.1, 0.1.5-1ubuntu0.2, 0.1.6-1ubuntu0.1
xdg-dbus-proxy-debugsource - update to 0.1.2-2
xdg-dbus-proxy-debuginfo - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.2-2
xdg-dbus-proxy-help - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.3-5
xdg-dbus-proxy (Debian package) - addressed in versions 0.1.4-3+deb12u1, 0.1.6-1+deb13u1
xdg-dbus-proxy-debugsource - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy-debuginfo - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - addressed in versions 0.1.7-1.fc42, 0.1.7-1.fc43, 0.1.7-1.fc44

External References

Related Security Bulletins