AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

Red HatCVE-2026-94422

Red Hat, Inc.: CVE records (CNA): code execution

Red Hat

CVE-2026-94422 · Published Oct 2, 2026

High8.7
Fix: upgrade to Red Hat or later (3 fixed versions below)
Red Hat advisory

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.

Affected versions

PackageAffectedFixed in
Fedora
Product
< 0.1.90.1.9
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat, Inc.: CVE records (CNA)
Product
< 0.1.90.1.9
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Certificate System 10: authentication bypass by spoofing
High8.1Oct 2
Red Hat FreeType: resource exhaustion
Medium5.5Oct 2
A flaw was found in 389-ds-base
Critical9.0Oct 2
Red Hat 389-ds-base: resource exhaustion
High7.5Oct 1
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1