GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnome-shell | Jul 30, 2024 | Dec 25, 2014 |
| Oracle_linux | — | Upgrade clutter-develUpgrade clutterUpgrade cogl-develUpgrade clutter-docUpgrade cogl-docUpgrade mutterUpgrade gnome-shell-browser-pluginUpgrade coglUpgrade mutter-develUpgrade gnome-shell | Oct 16, 2024 | Dec 25, 2014 |
| Suse | — | Upgrade gnome-settings-daemon-langUpgrade gnome-settings-daemon-develUpgrade gnome-settings-daemon | Dec 18, 2015 | Dec 25, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub