Packages
- xdg-desktop-portal - A portal frontend service for Flatpak and other desktop containment frameworks
Details
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the
fix for CVE-2026-40354 was incomplete and introduced a regression when
trashing files. This update fixes the problem and provides the
corresponding update for Ubuntu 26.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that XDG Desktop Portal incorrectly handled
trashing files. A local attacker could possibly use this issue to
delete arbitrary files on the host file system via a symlink attack.
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the
fix for CVE-2026-40354 was incomplete and introduced a regression when
trashing files. This update fixes the problem and provides the
corresponding update for Ubuntu 26.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that XDG Desktop Portal incorrectly handled
trashing files. A local attacker could possibly use this issue to
delete arbitrary files on the host file system via a symlink attack.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | xdg-desktop-portal – 1.21.1+ds-1ubuntu3.1 | ||
| xdg-desktop-portal-dev – 1.21.1+ds-1ubuntu3.1 | |||
| 24.04 LTS noble | xdg-desktop-portal – 1.18.4-1ubuntu2.24.04.3 | ||
| xdg-desktop-portal-dev – 1.18.4-1ubuntu2.24.04.3 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.