This bug was fixed in the package xdg-desktop-portal -
1.21.1+ds-1ubuntu5
---------------
xdg-desktop-portal (1.21.1+ds-1ubuntu5) stonking; urgency=medium
* SECURITY REGRESSION: Incomplete fix for CVE-2026-40354 (LP: #2166546)
- debian/patches/CVE-2026-40354-post1.patch: Get the fd of the file to
trash on the host in src/trash.c
- debian/patches/CVE-2026-40354-post2.patch: Check that the caller has
write access on the fd to trash in src/trash.c
- debian/patches/CVE-2026-40354-post3.patch: Never ignore the home trash
location in src/trash.c
- debian/patches/CVE-2026-40354-post4.patch: Add more debug logging in
src/trash.c
- debian/patches/CVE-2026-40354-post5.patch: Allow trash directories to
have any mode in src/trash.c
-- Kyle Kernick <[email protected]> Tue, 22 Sep 2026 16:40:46
-0600
** Changed in: xdg-desktop-portal (Ubuntu Stonking)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166546
Title:
CVE-2026-40354 fix (USN-8287-1) breaks the Trash portal for Flatpak
apps — upstream regression fix (#1982) not backported
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/xdg-desktop-portal/+bug/2166546/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs