From f3eef04384145cc2cbd2f29eb985c43026eb5a38 Mon Sep 17 00:00:00 2001 From: xiepengfei Date: Thu, 7 May 2026 14:59:28 +0800 Subject: [PATCH] fix(security): VPLUS-2026-34718 - fix DBus permission configuration - Implement method-level permission separation for DBus service - Default deny policy for all methods - Whitelist read-only methods (getAuthorizedInfo, getRemoveInfo, etc.) - Dangerous methods (aptUpdate, installDriver, disableInDevice) require authentication - Add comprehensive security policy documentation Security impact: - Fixes privilege escalation vulnerability (CVSS 8.1) - Prevents unauthorized access to root-level operations - Clear maintenance guidelines for future DBus method additions CVSS: 8.1 (High) Affected: All systems with deepin-devicemanager installed Fix version: 6.0.62 PMS: TASK-389221 --- .../org.deepin.devicecontrol.conf | 55 ++++++++++++++++++- 1 file changed, 52 insertions(+), 3 deletions(-) diff --git a/deepin-devicemanager-server/deepin-devicecontrol/org.deepin.devicecontrol.conf b/deepin-devicemanager-server/deepin-devicecontrol/org.deepin.devicecontrol.conf index 89c75e80c..b7c47402b 100644 --- a/deepin-devicemanager-server/deepin-devicecontrol/org.deepin.devicecontrol.conf +++ b/deepin-devicemanager-server/deepin-devicecontrol/org.deepin.devicecontrol.conf @@ -4,16 +4,65 @@ "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN" "http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd"> + - - - + + + + + + + + + + + + + + + +