Improper Validation of Unsafe Equivalence in Input in xdg-dbus-proxy - CVE-2026-34080
Published: April 10, 2026
Vulnerability identifier: #VU125785
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34080
CWE-ID: CWE-1289
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a policy parser issue. A remote attacker can bypass eavesdrop restrictions and intercept D-Bus messages.
Affected software
xdg-dbus-proxy
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
xdg-dbus-proxy (Ubuntu package)
xdg-dbus-proxy-debugsource
xdg-dbus-proxy-debuginfo
xdg-dbus-proxy
xdg-dbus-proxy-help
xdg-dbus-proxy (Debian package)
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
xdg-dbus-proxy (Ubuntu package)
xdg-dbus-proxy-debugsource
xdg-dbus-proxy-debuginfo
xdg-dbus-proxy
xdg-dbus-proxy-help
xdg-dbus-proxy (Debian package)
How to mitigate CVE-2026-34080
Install updates from vendor's website.
xdg-dbus-proxy - update to 0.1.7
xdg-dbus-proxy (Ubuntu package) - addressed in versions 0.1.2-1ubuntu0.1~esm1, 0.1.3-1ubuntu0.1, 0.1.5-1ubuntu0.2, 0.1.6-1ubuntu0.1
xdg-dbus-proxy-debugsource - update to 0.1.2-2
xdg-dbus-proxy-debuginfo - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.2-2
xdg-dbus-proxy-help - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.3-5
xdg-dbus-proxy (Debian package) - addressed in versions 0.1.4-3+deb12u1, 0.1.6-1+deb13u1
xdg-dbus-proxy-debugsource - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy-debuginfo - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - addressed in versions 0.1.7-1.fc42, 0.1.7-1.fc43, 0.1.7-1.fc44
xdg-dbus-proxy (Ubuntu package) - addressed in versions 0.1.2-1ubuntu0.1~esm1, 0.1.3-1ubuntu0.1, 0.1.5-1ubuntu0.2, 0.1.6-1ubuntu0.1
xdg-dbus-proxy-debugsource - update to 0.1.2-2
xdg-dbus-proxy-debuginfo - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.2-2
xdg-dbus-proxy-help - update to 0.1.2-2
xdg-dbus-proxy - update to 0.1.3-5
xdg-dbus-proxy (Debian package) - addressed in versions 0.1.4-3+deb12u1, 0.1.6-1+deb13u1
xdg-dbus-proxy-debugsource - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy-debuginfo - update to 0.1.5-150600.3.5.1
xdg-dbus-proxy - addressed in versions 0.1.7-1.fc42, 0.1.7-1.fc43, 0.1.7-1.fc44
External References
Related Security Bulletins
- Information disclosure in xdg-dbus-proxy
- Debian update for xdg-dbus-proxy
- Ubuntu update for xdg-dbus-proxy
- Fedora 44 update for xdg-dbus-proxy
- Fedora 43 update for xdg-dbus-proxy
- Fedora 42 update for xdg-dbus-proxy
- Anolis OS update for xdg-dbus-proxy
- openEuler 24.03 LTS SP1 update for xdg-dbus-proxy
- openEuler 24.03 LTS update for xdg-dbus-proxy
- openEuler 24.03 LTS SP3 update for xdg-dbus-proxy
- Debian update for xdg-dbus-proxy
- openEuler 22.03 LTS SP4 update for xdg-dbus-proxy
- openEuler 20.03 LTS SP4 update for xdg-dbus-proxy
- Ubuntu update for xdg-dbus-proxy
- SUSE update for xdg-dbus-proxy