EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8287-2: XDG Desktop Portal regression

Official source
EudorIA operational summary

What it means

Priority 40/100

La vulnerabilità CVE-2026-40354 riguarda la gestione errata del trashing files nel XDG Desktop Portal, che potrebbe permettere a un attaccante locale di eliminare file arbitrari tramite un attacco symlink. L'aggiornamento USN-8287-2 risolve la regressione introdotta da USN-8287-1. La patch è disponibile per Ubuntu 26.04 LTS.

Why it matters

Per le PMI italiane, questa vulnerabilità potrebbe compromettere la sicurezza dei sistemi Linux, specialmente se gestiscono dati sensibili o operazioni critiche. La mancanza di patch potrebbe portare a perdite di dati o interruzioni di servizio.

Potential operational benefits

  • Riduzione della superficie esposta a vulnerabilità locali
  • Miglioramento della gestione delle operazioni di eliminazione di file
  • Aumento della protezione contro attacchi symlink
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMonitoraggio / SIEMFirewall NGFW / IPS
AudienceITSOC
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
23/09/2026 20:40
CVE
CVE-2026-40354
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source