A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
CVSS Details
- CVSS 3.1 Base Score: 6.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdm3 | Jul 30, 2024 | Dec 28, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 28, 2020 |
| Suse | — | Upgrade gdm-systemdUpgrade typelib-1_0-Gdm-1_0Upgrade gdm-develUpgrade gdmflexiserverUpgrade libgdm1Upgrade gdm-schemaUpgrade gdm-langUpgrade gdm | Aug 9, 2024 | Dec 28, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 28, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub