SWHKD is a display protocol-independent hotkey daemon made in Rust. In SWHKD versions 1.1.5 and prior, SWHKD uses the /tmp/swhkd.pid pathname. As /tmp is accessible to all users, there can be an information leak or denial of service. No known workarounds exist. A patch is available on the 1.1.0 branch of the repository.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-377",
"CWE-59"
],
"nvd_published_at": "2022-03-30T00:15:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2022-04-01T15:15:36Z"
}