Opened 6 months ago

Closed 6 months ago

#23127 closed enhancement (fixed)

xdg-desktop-portal-1.20.4

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by pierre, 6 months ago

Summary: xdg-desktop-portal--1.20.4 → xdg-desktop-portal-1.20.4

comment:2 by Xi Ruoyao, 6 months ago

I heard it contains the change related to some flatpak vulnerability but I'm unsure if it counts as a priority=high.

comment:3 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:4 by Joe Locash, 6 months ago

Changes in 1.20.4
=================
Released: 2026-04-08

- Prevent trashing of arbitrary host files (GHSA-rqr9-jwwf-wxgj)

Fixed at b16a999475.

I'm going to leave this open for now. Right now it looks like this only affects flatpak.

comment:5 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to Douglas R. Reno
Status: assigned → new

comment:6 by Bruce Dubbs, 6 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory

comment:7 by Douglas R. Reno, 6 months ago

Priority: normal → elevated

In my interpretation it looks like this isn't specific to Flatpak apps, but rather anything that uses the Trash portal. This may include programs such as Nautilus or Dolphin

​https://github.com/flatpak/xdg-desktop-portal/security/advisories/GHSA-rqr9-jwwf-wxgj rates it as Moderate but with no CVE (which is fair honestly, it would be close to a duplicate of the Flatpak-specific issue)

comment:8 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-043 issued.

Note: See TracTickets for help on using tickets.