USN-8287-2

Source
https://ubuntu.com/security/notices/USN-8287-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8287-2.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-8287-2
Published
2026-09-23T18:40:07Z
Modified
2026-09-24T07:30:08Z
Summary
xdg-desktop-portal regression
Details

USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS.

We apologize for the inconvenience.

Original advisory details:

It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

References

Affected packages

Ubuntu:24.04:LTS / xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.18.4-1ubuntu2.24.04.3

Affected versions

1.*
1.18.0-1ubuntu1
1.18.2-1ubuntu1
1.18.2-1ubuntu3
1.18.2-1ubuntu4
1.18.3-1ubuntu1
1.18.4-1ubuntu2
1.18.4-1ubuntu2.24.04.1
1.18.4-1ubuntu2.24.04.2

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "xdg-desktop-portal",
            "binary_version":  "1.18.4-1ubuntu2.24.04.3"
        },
        {
            "binary_name":  "xdg-desktop-portal-tests",
            "binary_version":  "1.18.4-1ubuntu2.24.04.3"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [],
    "ecosystem":  "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8287-2.json"

Ubuntu:26.04:LTS / xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.21.1+ds-1ubuntu3.1

Affected versions

1.*
1.20.3+ds-1ubuntu1
1.20.3+ds-1ubuntu2
1.21.0+ds-1ubuntu3
1.21.0+ds-1ubuntu4
1.21.0+ds-1ubuntu6
1.21.0+ds-1ubuntu7
1.21.0+ds-1ubuntu8
1.21.1+ds-1ubuntu1
1.21.1+ds-1ubuntu2
1.21.1+ds-1ubuntu3

Ecosystem specific

{
    "availability":  "No subscription required",
    "binaries":  [
        {
            "binary_name":  "xdg-desktop-portal",
            "binary_version":  "1.21.1+ds-1ubuntu3.1"
        },
        {
            "binary_name":  "xdg-desktop-portal-tests",
            "binary_version":  "1.21.1+ds-1ubuntu3.1"
        }
    ]
}

Database specific

cves_map
{
    "cves":  [],
    "ecosystem":  "Ubuntu:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8287-2.json"