UbuntuUpdates.org

Package "xdg-desktop-portal"

Name: xdg-desktop-portal

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • desktop integration portal - automated tests

Latest version: 1.18.4-1ubuntu2.24.04.2
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "xdg-desktop-portal" in Noble

Repository Area Version
base universe 1.18.3-1ubuntu1
base main 1.18.3-1ubuntu1
security main 1.18.4-1ubuntu2.24.04.2
updates universe 1.18.4-1ubuntu2.24.04.2
updates main 1.18.4-1ubuntu2.24.04.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.18.4-1ubuntu2.24.04.2 2026-05-20 19:07:23 UTC

  xdg-desktop-portal (1.18.4-1ubuntu2.24.04.2) noble-security; urgency=medium

  * SECURITY UPDATE: Symlink Redirection Attack in g_file_trash
    - debian/patches/CVE-2026-40354-pre1.patch: Add libglnx dependency in
      meson.build and subprojects/libglnx.wrap
    - debian/patches/CVE-2026-40354-pre2.patch: use Call over Requests in
      src/gamemode.c,
      ../memory-monitor.c,
      ../network-monitor.c,
      ../proxy-resolver.c,
      ../realtime.c,
      ../trash.c, and
      ../xdg-desktop-portal.c
    - debian/patches/CVE-2026-40354-1.patch: Use File Descriptors rather than
      g_file_trash to avoid race conditions when trashing file in src/trash.c
    - debian/patches/CVE-2026-40354-2.patch: Fix trashing files on older
      versions of glib in src/trash.c
    - CVE-2026-40354
  * xdg-desktop-portal_1.18.4.orig-libglnx.tar.gz: Add vendored libglnx
    at ccea836b799256420788c463a638ded0636b1632.
  * debian/rules: Add symlink to vendored libglnx in submodules/libglnx
  * debian/clean: Remove vendored libglnx symlink after build

 -- Kyle Kernick <email address hidden> Thu, 23 Apr 2026 15:56:27 -0600

CVE-2026-40354 Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack o



About   -   Send Feedback to @ubuntu_updates