Bug 2291222 (CVE-2024-36041) - CVE-2024-36041 plasma-workspace/ksmserver: Unauthorized users can access session manager
Summary: CVE-2024-36041 plasma-workspace/ksmserver: Unauthorized users can access sess...
Keywords:
Status: NEW
Alias: CVE-2024-36041
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2291223 2291224
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-06-10 20:59 UTC by Marco Benatto
Modified: 2024-06-10 20:59 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marco Benatto 2024-06-10 20:59:21 UTC
Overview
========
KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE
based purely on the host, allowing all local connections. This allows
another user on the same machine to gain access to the session
manager.

A well crafted client could use the session restore feature to execute
arbitrary code as the user on the next boot.

Comment 1 Marco Benatto 2024-06-10 20:59:37 UTC
Created plasma-workspace tracking bugs for this issue:

Affects: epel-all [bug 2291223]
Affects: fedora-all [bug 2291224]


Note You need to log in before you can comment on or make changes to this bug.