daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-dbg" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-dbgsym" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-theme-circles" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-theme-elarun" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-theme-maldives" }, { "binary_version": "0.13.0-1ubuntu5", "binary_name": "sddm-theme-maui" } ] }