A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
{
"binaries": [
{
"binary_version": "3.36.3-0ubuntu0.20.04.4",
"binary_name": "gdm3"
},
{
"binary_version": "3.36.3-0ubuntu0.20.04.4",
"binary_name": "gir1.2-gdm-1.0"
},
{
"binary_version": "3.36.3-0ubuntu0.20.04.4",
"binary_name": "libgdm-dev"
},
{
"binary_version": "3.36.3-0ubuntu0.20.04.4",
"binary_name": "libgdm1"
}
]
}
{
"binaries": [
{
"binary_version": "42.0-1ubuntu7.22.04.4",
"binary_name": "gdm3"
},
{
"binary_version": "42.0-1ubuntu7.22.04.4",
"binary_name": "gir1.2-gdm-1.0"
},
{
"binary_version": "42.0-1ubuntu7.22.04.4",
"binary_name": "libgdm-dev"
},
{
"binary_version": "42.0-1ubuntu7.22.04.4",
"binary_name": "libgdm1"
}
]
}