An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-sddm | Jan 4, 2021 | Nov 4, 2020 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Nov 4, 2020 | |
| Debian | debian-upgrade-sddm | Nov 9, 2020 | Nov 4, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-x11-misc-sddm | Feb 5, 2024 | Nov 4, 2020 | |
| Suse | — | suse-upgrade-sddmsuse-upgrade-sddm-branding-opensusesuse-upgrade-sddm-branding-slesuse-upgrade-sddm-branding-upstream | Feb 17, 2021 | Nov 4, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub