Home / mailings [USN-8287-2] XDG Desktop Portal regression
Posted on 24 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8287-2
September 23, 2026
xdg-desktop-portal regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
Summary:
USN-8287-1 introduced a regression in XDG Desktop Portal
Software Description:
- xdg-desktop-portal: A portal frontend service for Flatpak and other desktop containment frameworks
Details:
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the
fix for CVE-2026-40354 was incomplete and introduced a regression when
trashing files. This update fixes the problem and provides the
corresponding update for Ubuntu 26.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that XDG Desktop Portal incorrectly handled
trashing files. A local attacker could possibly use this issue to
delete arbitrary files on the host file system via a symlink attack.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
xdg-desktop-portal 1.21.1+ds-1ubuntu3.1
xdg-desktop-portal-dev 1.21.1+ds-1ubuntu3.1
Ubuntu 24.04 LTS
xdg-desktop-portal 1.18.4-1ubuntu2.24.04.3
xdg-desktop-portal-dev 1.18.4-1ubuntu2.24.04.3
In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-8287-2
https://ubuntu.com/security/notices/USN-8287-1
https://bugs.launchpad.net/ubuntu/+source/xdg-desktop-portal/+bug/2166546
Package Information:
https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.21.1+ds-1ubuntu3.1
https://launchpad.net/ubuntu/+source/xdg-desktop-portal/1.18.4-1ubuntu2.24.04.3
--===============7442844132063309198==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
