Описание
Security update for xdg-desktop-portal
This update for xdg-desktop-portal fixes the following issue:
- CVE-2026-40354: File deletion via symlink attack (bsc#1262045).
Список пакетов
Container suse/kiosk/firefox-esr:latest
xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
xdg-desktop-portal-1.18.2-150600.4.6.1
xdg-desktop-portal-devel-1.18.2-150600.4.6.1
xdg-desktop-portal-lang-1.18.2-150600.4.6.1
Ссылки
- Link for SUSE-SU-2026:2712-1
- E-Mail link for SUSE-SU-2026:2712-1
- SUSE Security Ratings
- SUSE Bug 1262045
- SUSE CVE CVE-2026-40354 page
Описание
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
Затронутые продукты
Container suse/kiosk/firefox-esr:latest:xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-devel-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-lang-1.18.2-150600.4.6.1
Ссылки
- CVE-2026-40354
- SUSE Bug 1262045