Time-of-check Time-of-use (TOCTOU) Race Condition in xdg-desktop-portal - CVE-2026-40354
Published: April 8, 2026 / Updated: September 14, 2026
Vulnerability identifier: #VU125194
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40354
CWE-ID: CWE-367
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A remote attacker can delete arbitrary files on the system.
Affected software
xdg-desktop-portal
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Desktop Applications Module
openSUSE Leap
Anolis OS
openEuler
Ubuntu
xdg-desktop-portal-lang
xdg-desktop-portal-devel
xdg-desktop-portal-debuginfo
xdg-desktop-portal-debugsource
xdg-desktop-portal
xdg-desktop-portal (Ubuntu package)
xdg-desktop-portal-doc
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Desktop Applications Module
openSUSE Leap
Anolis OS
openEuler
Ubuntu
xdg-desktop-portal-lang
xdg-desktop-portal-devel
xdg-desktop-portal-debuginfo
xdg-desktop-portal-debugsource
xdg-desktop-portal
xdg-desktop-portal (Ubuntu package)
xdg-desktop-portal-doc
How to mitigate CVE-2026-40354
Install updates from vendor's website.
xdg-desktop-portal - update to 1.20.4
xdg-desktop-portal-lang - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-devel - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-debuginfo - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-debugsource - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal (Ubuntu package) - addressed in versions 1.18.4-1ubuntu2.24.04.3, 1.21.1+ds-1ubuntu3.1
xdg-desktop-portal-devel - update to 1.20.4-1
xdg-desktop-portal-debugsource - update to 1.20.4-1
xdg-desktop-portal-debuginfo - update to 1.20.4-1
xdg-desktop-portal - update to 1.20.4-1
xdg-desktop-portal - update to 1.20.4-1
xdg-desktop-portal-devel - update to 1.20.4-1
xdg-desktop-portal-doc - update to 1.20.4-1
xdg-desktop-portal-lang - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-devel - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-debuginfo - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal-debugsource - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal - addressed in versions 1.10.1-150400.3.11.1, 1.18.2-150600.4.6.1
xdg-desktop-portal (Ubuntu package) - addressed in versions 1.18.4-1ubuntu2.24.04.3, 1.21.1+ds-1ubuntu3.1
xdg-desktop-portal-devel - update to 1.20.4-1
xdg-desktop-portal-debugsource - update to 1.20.4-1
xdg-desktop-portal-debuginfo - update to 1.20.4-1
xdg-desktop-portal - update to 1.20.4-1
xdg-desktop-portal - update to 1.20.4-1
xdg-desktop-portal-devel - update to 1.20.4-1
xdg-desktop-portal-doc - update to 1.20.4-1
External References
Related Security Bulletins
- Time-of-check Time-of-use (TOCTOU) Race Condition in xdg-desktop-portal
- openEuler 24.03 LTS update for xdg-desktop-portal
- openEuler 24.03 LTS SP3 update for xdg-desktop-portal
- openEuler 24.03 LTS SP1 update for xdg-desktop-portal
- SUSE update for xdg-desktop-portal
- SUSE update for xdg-desktop-portal
- Anolis OS update for xdg-desktop-portal
- Ubuntu update for xdg-desktop-portal