A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.
{ "binaries": [ { "binary_version": "3.36.3-0ubuntu0.20.04.4", "binary_name": "gdm3" }, { "binary_version": "3.36.3-0ubuntu0.20.04.4", "binary_name": "gir1.2-gdm-1.0" }, { "binary_version": "3.36.3-0ubuntu0.20.04.4", "binary_name": "libgdm-dev" }, { "binary_version": "3.36.3-0ubuntu0.20.04.4", "binary_name": "libgdm1" } ] }
{ "binaries": [ { "binary_version": "42.0-1ubuntu7.22.04.4", "binary_name": "gdm3" }, { "binary_version": "42.0-1ubuntu7.22.04.4", "binary_name": "gir1.2-gdm-1.0" }, { "binary_version": "42.0-1ubuntu7.22.04.4", "binary_name": "libgdm-dev" }, { "binary_version": "42.0-1ubuntu7.22.04.4", "binary_name": "libgdm1" } ] }