Red HatCVE-2026-94422
Red Hat, Inc.: CVE records (CNA): code execution
Fix: upgrade to Red Hat or later (3 fixed versions below)
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Fedora Product | < 0.1.9 | 0.1.9 |
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat, Inc.: CVE records (CNA) Product | < 0.1.9 | 0.1.9 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
- www.cve.org/CVERecord?id=CVE-2026-94422
- nvd.nist.gov/vuln/detail/CVE-2026-94422
- access.redhat.com/security/cve/CVE-2026-94422
- bugzilla.redhat.com/show_bug.cgi?id=2542235
- github.com/flatpak/xdg-dbus-proxy/commit/e4465a0dfe96da3b39929a30a1ac3a22b16223e3
- github.com/flatpak/xdg-dbus-proxy/commit/e5702fca4dba9600721921fbca2dbc39dc5ca400
- github.com/flatpak/xdg-dbus-proxy/commit/fc027f759316fb2a6c45648200b6f100202eb84e
- github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
- www.openwall.com/lists/oss-security/2026/09/23/5
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 2 | Red Hat Certificate System 10: authentication bypass by spoofing | High8.1 | No fix yet |
| Oct 2 | Red Hat FreeType: resource exhaustion | Medium5.5 | No fix yet |
| Oct 2 | A flaw was found in 389-ds-base | Critical9.0 | No fix yet |
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |