CVE-2017-15131: Freedesktop Xdg-User-Dirs

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.

Affected products

  • Freedesktop Xdg-User-Dirs: before 0.15.5 (fixed in 0.15.5)
  • Red Hat Enterprise Linux: version 7.0 only

Published 2018-01-09. Last modified 2026-06-17.