Opened 3 months ago

Closed 3 months ago

#23470 closed enhancement (fixed)

xdg-desktop-portal-1.22.1

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Joe Locash, 3 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 3 months ago

Priority: normal → elevated
Changes in 1.22.1
=================
Released: 2026-06-17

Security fixes:

- Fix a security issue which allows a malicious sandboxed applications to
  redirect drag-and-drop and copy-paste data to itself via a predictable
  key in `FileTransfer.RetrieveFiles` (GHSA-c5cf-79w8-pvfh)
- Fix a security issue which allows a malicious sandboxed applications to gain
  arbitrary write access to nonexistent files outside of the sandbox via the
  "files" option in `FileChooser.SaveFiles` (GHSA-cm83-2936-gxjm)
- Validate all App IDs in the Document Portal to prevent malicious applications
  from providing a well-crafted App ID which causes the parsing of arbitrary
  files on the host as `Glib.KeyFile`s (#2023)

Enhancements:

- Disable PipeWire's realtime module to prevent deadlocks (#2012)

comment:3 by Joe Locash, 3 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at a409ee3403. Leaving open for SA.

comment:4 by Douglas R. Reno, 3 months ago

Priority: elevated → high

GHSA-cm83-2936-gxjm is rated as Critical

comment:5 by Douglas R. Reno, 3 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-128 issued

Note: See TracTickets for help on using tickets.