Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2712-1

Опубликовано: 30 июн. 2026
Источник: suse-cvrf

Описание

Security update for xdg-desktop-portal

This update for xdg-desktop-portal fixes the following issue:

  • CVE-2026-40354: File deletion via symlink attack (bsc#1262045).

Список пакетов

Container suse/kiosk/firefox-esr:latest
xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
xdg-desktop-portal-1.18.2-150600.4.6.1
xdg-desktop-portal-devel-1.18.2-150600.4.6.1
xdg-desktop-portal-lang-1.18.2-150600.4.6.1

Описание

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-devel-1.18.2-150600.4.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:xdg-desktop-portal-lang-1.18.2-150600.4.6.1

Ссылки