-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Apr 2026 11:21:21 +0200 Source: xdg-dbus-proxy Architecture: source Version: 0.1.2-2+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Closes: 1132939 Changes: xdg-dbus-proxy (0.1.2-2+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * Backport patches from 0.1.4-3+deb12u1 (thanks Simon McVittie): * d/p/Fix-GVariant-reference-leaks.patch: Add patch from upstream 0.1.6 fixing some memory leaks. As well as being a desirable bug fix, this is necessary for the fix for CVE-2026-34080 to apply cleanly. * d/p/flatpak-proxy-Use-g_autoptr-in-validate_arg0_match.patch, d/p/Improve-detection-of-eavesdrop-true.patch: Fix detection of eavesdrop=true match rules, resolving a vulnerability in which a malicious or compromised Flatpak app could monitor D-Bus traffic that it was not intended to be able to access. (CVE-2026-34080) (Closes: #1132939) Checksums-Sha1: 23afc29b90ac2d4ee6f703e229ff8e25039aded7 2236 xdg-dbus-proxy_0.1.2-2+deb11u1.dsc df150cac11b092e3258f7f41bb81246abf77bb75 119264 xdg-dbus-proxy_0.1.2.orig.tar.xz fa6426ad6fe52765ab1559ffa9a690c736d02b59 5728 xdg-dbus-proxy_0.1.2-2+deb11u1.debian.tar.xz 0244d71fd41574cf5d30fc254fdfc9284f56bed7 7639 xdg-dbus-proxy_0.1.2-2+deb11u1_source.buildinfo Checksums-Sha256: a955174c129a78e74eb9ffd30db0b6e971a09640519b762dabc88e3862aa70d6 2236 xdg-dbus-proxy_0.1.2-2+deb11u1.dsc 1749d6f9f46dcc9edc87725641cf56cf91dcad1b01707891ea0850c1000c520f 119264 xdg-dbus-proxy_0.1.2.orig.tar.xz 993490ab8760c237c881f860c93e8c050141391290be98a3bcb1c831f78b6810 5728 xdg-dbus-proxy_0.1.2-2+deb11u1.debian.tar.xz 51babda7dcac5cc9f9891976976370b22123eda483fca2d59768df4f1a1c75bd 7639 xdg-dbus-proxy_0.1.2-2+deb11u1_source.buildinfo Files: d8621a329e5f80a5e77a997282f43256 2236 admin optional xdg-dbus-proxy_0.1.2-2+deb11u1.dsc 19cb184734e0f080dfe335fd9ffc61b1 119264 admin optional xdg-dbus-proxy_0.1.2.orig.tar.xz 29c704b8f1c19552c9f3da8788a1018e 5728 admin optional xdg-dbus-proxy_0.1.2-2+deb11u1.debian.tar.xz 6973c27cb1321c4c50a9b96223572443 7639 admin optional xdg-dbus-proxy_0.1.2-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmnnVC0ACgkQnUbEiOQ2 gwLzfBAAh5fgkqFnstdJAS4Tb/cPWerfeON922kYiv4jnKxVDVzPkFtkKmzq/mz7 ZIDPiYDN11/hh60Dgr9DsTuVcdUGlTcDdr9PnVsWU+fs4eaZ41SAokGVc9bR1207 6oYLMYaU+PrA77xMLDxxtRqUYwlv6SG96t8a6SDC0NzYqpTMDsMoroOTW13dsrpB HSmpKDpSdUsLc2aISNHgDmHr2cSY9G7PvsOmFUFdb9sJf0fd1C3RAtEOKjbvBkzg l2TKG/WkhdklQkpUbLQF+2SLPiS9QbAfhMeRRJOSgnJPmZh/uNEGNaoMUt2BGdis g6m+cyRF8eG20Y85hL4E9qGIJ3IOmpIgvEG/XZZPhE9OwC69ybVD/gHx8uIvDFuP bfYg/CCR5688PWi/wueOpghQ0yE6bnj4kZ+vX63Xq+WaV0KvqJp7QxLeoNg2eO2s DWd+aTGRJCQNIevqttODerqh3p9U2hTd94PLNnKH+4fKR43IurU4Ha4M9kg2qvdk jW4qbpZuZ//lg0Qk99iccKY2zK3P2bKQPje5T6KiVB2ejC/scpaBgwDWknzw1GKt gwXS0m1JLs9tph/fgm5kVt9K2cDdX1yYUxO6wc6LwP55BpyL9998UCJiL1KcE3hV yWOnn1XfBXZ++1Hbglhbt9wSdfVT5UC04lKI/d+u6w3ZivgPOXg= =wURm -----END PGP SIGNATURE-----