USN-8287-2: XDG Desktop Portal regression
Ubuntu fixes an incomplete XDG Desktop Portal patch for CVE-2026-40354 that broke file trashing.
Ubuntu USN-8287-2 says the earlier fix for CVE-2026-40354 in XDG Desktop Portal was incomplete and introduced a regression when trashing files. This update corrects that problem and supplies the corresponding package for Ubuntu 26.04 LTS. The original flaw let a local attacker possibly delete arbitrary files on the host filesystem through a symlink while trashing files. The notice does not report exploitation in the wild.
- USN-8287-1 left CVE-2026-40354 only partly fixed.
- The bad fix regressed trashing files on Ubuntu 26.04 LTS.
- A local symlink could delete arbitrary host files.
- The notice does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-403546.3<1%Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on…published · flatpak xdg-desktop-portal
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40354 | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on… Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. NVD description · AI analysis pending |
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.
This source does not provide full text. Read it at ubuntu.com.