An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp. Upstream patch: https://github.com/sddm/sddm/commit/147cec383892d143b5e02daa70f1e7def50f5d98
Created sddm tracking bugs for this issue: Affects: epel-7 [bug 1603424] Affects: fedora-all [bug 1603423]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.