daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "sddm",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-dbg",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-dbgsym",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-theme-circles",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-theme-elarun",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-theme-maldives",
            "binary_version": "0.13.0-1ubuntu5"
        },
        {
            "binary_name": "sddm-theme-maui",
            "binary_version": "0.13.0-1ubuntu5"
        }
    ]
}