daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "sddm", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-dbg", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-dbgsym", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-theme-circles", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-theme-elarun", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-theme-maldives", "binary_version": "0.13.0-1ubuntu5" }, { "binary_name": "sddm-theme-maui", "binary_version": "0.13.0-1ubuntu5" } ] }