USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.