A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
{ "binaries": [ { "binary_name": "gdm3", "binary_version": "3.36.3-0ubuntu0.20.04.4" }, { "binary_name": "gir1.2-gdm-1.0", "binary_version": "3.36.3-0ubuntu0.20.04.4" }, { "binary_name": "libgdm-dev", "binary_version": "3.36.3-0ubuntu0.20.04.4" }, { "binary_name": "libgdm1", "binary_version": "3.36.3-0ubuntu0.20.04.4" } ] }
{ "binaries": [ { "binary_name": "gdm3", "binary_version": "42.0-1ubuntu7.22.04.4" }, { "binary_name": "gir1.2-gdm-1.0", "binary_version": "42.0-1ubuntu7.22.04.4" }, { "binary_name": "libgdm-dev", "binary_version": "42.0-1ubuntu7.22.04.4" }, { "binary_name": "libgdm1", "binary_version": "42.0-1ubuntu7.22.04.4" } ] }