[Pkg-utopia-maintainers] Bug#1132958: xdg-desktop-portal: GHSA-rqr9-jwwf-wxgj: Race condition in trash portal vs. symlinks

Simon McVittie smcv at debian.org
Tue Apr 14 20:26:26 BST 2026


On Mon, 13 Apr 2026 at 20:48:21 +0000, Moritz Mühlenhoff wrote:
(on a different bug)
>As or the remaining related security issue (xdg-desktop-portal), I'm inclined
>to not fix this via a DSA, the impact seem really limited. But if you prefer
>to also see this fix via security.d.o we can surely also revisit.

Thanks, I'll retarget the proposed trixie update to the stable release 
team rather than the security team if you don't want to do this as a 
DSA, and treat it as lower-urgency.

I wasn't looking forward to backporting this one to bookworm, which is 
going to be rather more involved (because the backport would have to add 
all of libglnx). At the moment I'm inclined to get this fixed in trixie 
and leave it at that, and if someone else (the LTS team?) wants to 
backport into bookworm, they can.

     smcv



More information about the Pkg-utopia-maintainers mailing list