[Pkg-utopia-maintainers] Bug#1132958: xdg-desktop-portal: GHSA-rqr9-jwwf-wxgj: Race condition in trash portal vs. symlinks
Simon McVittie
smcv at debian.org
Tue Apr 14 20:26:26 BST 2026
On Mon, 13 Apr 2026 at 20:48:21 +0000, Moritz Mühlenhoff wrote:
(on a different bug)
>As or the remaining related security issue (xdg-desktop-portal), I'm inclined
>to not fix this via a DSA, the impact seem really limited. But if you prefer
>to also see this fix via security.d.o we can surely also revisit.
Thanks, I'll retarget the proposed trixie update to the stable release
team rather than the security team if you don't want to do this as a
DSA, and treat it as lower-urgency.
I wasn't looking forward to backporting this one to bookworm, which is
going to be rather more involved (because the backport would have to add
all of libglnx). At the moment I'm inclined to get this fixed in trixie
and leave it at that, and if someone else (the LTS team?) wants to
backport into bookworm, they can.
smcv
More information about the Pkg-utopia-maintainers
mailing list