In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
{ "binaries": [ { "binary_name": "gnome-shell", "binary_version": "3.36.9-0ubuntu0.20.04.4" }, { "binary_name": "gnome-shell-common", "binary_version": "3.36.9-0ubuntu0.20.04.4" }, { "binary_name": "gnome-shell-dbgsym", "binary_version": "3.36.9-0ubuntu0.20.04.4" }, { "binary_name": "gnome-shell-extension-prefs", "binary_version": "3.36.9-0ubuntu0.20.04.4" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "gnome-shell", "binary_version": "42.9-0ubuntu2.2" }, { "binary_name": "gnome-shell-common", "binary_version": "42.9-0ubuntu2.2" }, { "binary_name": "gnome-shell-dbgsym", "binary_version": "42.9-0ubuntu2.2" }, { "binary_name": "gnome-shell-extension-prefs", "binary_version": "42.9-0ubuntu2.2" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "gnome-shell", "binary_version": "46.0-0ubuntu6~24.04.3" }, { "binary_name": "gnome-shell-common", "binary_version": "46.0-0ubuntu6~24.04.3" }, { "binary_name": "gnome-shell-dbgsym", "binary_version": "46.0-0ubuntu6~24.04.3" }, { "binary_name": "gnome-shell-extension-prefs", "binary_version": "46.0-0ubuntu6~24.04.3" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }