UBUNTU-CVE-2026-40354

Source
https://ubuntu.com/security/CVE-2026-40354
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-40354
Upstream
  • CVE-2026-40354
Downstream
Related
Published
2026-04-11T01:16:00Z
Modified
2026-05-27T16:45:07.262188296Z
Severity
  • 2.9 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on gfiletrash.

References

Affected packages

Ubuntu:16.04:LTS
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.3-0ubuntu0.0

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.3-0ubuntu0.0",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.0.3-0ubuntu0.0",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"
Ubuntu:18.04:LTS
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8-2
0.8-3
0.9-1
0.9-2
0.10-0ubuntu1
0.10-2
0.10-4
0.11-1
1.*
1.0.3-0ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.3-0ubuntu0.2",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.0.3-0ubuntu0.2",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"
Ubuntu:20.04:LTS
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.2-2
1.4.2-3
1.6.0-1
1.6.0-1ubuntu1
1.6.0-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.6.0-1ubuntu2",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.6.0-1ubuntu2",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"
Ubuntu:22.04:LTS
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.1-1build1
1.10.1-2
1.10.1-4
1.12.1-1
1.12.1-1build1
1.12.1-1ubuntu1
1.14.1-1
1.14.1-2
1.14.2-1
1.14.2-1ubuntu1
1.14.2-1ubuntu2
1.14.3-0ubuntu2
1.14.3-0ubuntu2.22.04.1
1.14.4-1ubuntu1~22.04.1
1.14.4-1ubuntu2~22.04.1
1.14.4-1ubuntu2~22.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.14.4-1ubuntu2~22.04.2",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.14.4-1ubuntu2~22.04.2",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"
Ubuntu:24.04:LTS
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.4-1ubuntu2.24.04.2

Affected versions

1.*
1.18.0-1ubuntu1
1.18.2-1ubuntu1
1.18.2-1ubuntu3
1.18.2-1ubuntu4
1.18.3-1ubuntu1
1.18.4-1ubuntu2
1.18.4-1ubuntu2.24.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.18.4-1ubuntu2.24.04.2",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.18.4-1ubuntu2.24.04.2",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"
Ubuntu:25.10
xdg-desktop-portal

Package

Name
xdg-desktop-portal
Purl
pkg:deb/ubuntu/xdg-desktop-portal?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.20.3+ds-1ubuntu1.1

Affected versions

1.*
1.20.0+ds-2ubuntu1
1.20.0+ds-2ubuntu2
1.20.0+ds-2ubuntu3
1.20.3+ds-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.20.3+ds-1ubuntu1.1",
            "binary_name": "xdg-desktop-portal"
        },
        {
            "binary_version": "1.20.3+ds-1ubuntu1.1",
            "binary_name": "xdg-desktop-portal-tests"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-40354.json"