USN-6843-1

Source
https://ubuntu.com/security/notices/USN-6843-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6843-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6843-1
Upstream
Related
Published
2024-06-26T12:12:09Z
Modified
2026-04-24T09:49:32.027624Z
Summary
plasma-workspace vulnerability
Details

Fabian Vogt discovered that Plasma Workspace incorrectly handled connections via ICE. A local attacker could possibly use this issue to gain access to another user's session manager and execute arbitrary code.

References

Affected packages

Ubuntu:20.04:LTS / plasma-workspace

Package

Name
plasma-workspace
Purl
pkg:deb/ubuntu/plasma-workspace@4:5.18.8-0ubuntu0.2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:5.18.8-0ubuntu0.2

Affected versions

4:5.*
4:5.16.5-0ubuntu1
4:5.16.5-0ubuntu2
4:5.17.2-0ubuntu1
4:5.17.3-0ubuntu1
4:5.17.4-0ubuntu1
4:5.17.4-0ubuntu2
4:5.17.4-0ubuntu3
4:5.17.5-0ubuntu1
4:5.17.90-0ubuntu1
4:5.17.90-0ubuntu2
4:5.18.0a-0ubuntu1
4:5.18.1-0ubuntu1
4:5.18.2-0ubuntu2
4:5.18.3-0ubuntu1
4:5.18.3-0ubuntu2
4:5.18.4.1-0ubuntu1
4:5.18.5-0ubuntu0.1
4:5.18.8-0ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libcolorcorrect5",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "libkworkspace5-5",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "libnotificationmanager1",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "libplasma-geolocation-interface5",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "libtaskmanager6",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "libweather-ion7",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "plasma-workspace",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "plasma-workspace-wayland",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        },
        {
            "binary_name": "sddm-theme-breeze",
            "binary_version": "4:5.18.8-0ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:20.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6843-1.json"

Ubuntu:22.04:LTS / plasma-workspace

Package

Name
plasma-workspace
Purl
pkg:deb/ubuntu/plasma-workspace@4:5.24.7-0ubuntu0.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:5.24.7-0ubuntu0.2

Affected versions

4:5.*
4:5.22.5-0ubuntu1
4:5.23.0-0ubuntu1
4:5.23.2-0ubuntu1
4:5.23.3-0ubuntu1
4:5.23.4-0ubuntu1
4:5.23.4-0ubuntu2
4:5.23.5-0ubuntu1
4:5.23.90-0ubuntu1
4:5.23.90-0ubuntu2
4:5.24.0b-0ubuntu1
4:5.24.1-0ubuntu1
4:5.24.2-0ubuntu1
4:5.24.3-0ubuntu1
4:5.24.3-0ubuntu3
4:5.24.4-0ubuntu1
4:5.24.6-0ubuntu0.1
4:5.24.7-0ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libcolorcorrect5",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libkfontinst5",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libkfontinstui5",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libkworkspace5-5",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libnotificationmanager1",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libplasma-geolocation-interface5",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libtaskmanager6",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "libweather-ion7",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "plasma-workspace",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "plasma-workspace-data",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "plasma-workspace-wayland",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        },
        {
            "binary_name": "sddm-theme-breeze",
            "binary_version": "4:5.24.7-0ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6843-1.json"

Ubuntu:24.04:LTS / plasma-workspace

Package

Name
plasma-workspace
Purl
pkg:deb/ubuntu/plasma-workspace@4:5.27.11-0ubuntu4.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:5.27.11-0ubuntu4.1

Affected versions

4:5.*
4:5.27.8-0ubuntu1
4:5.27.9.1-0ubuntu1
4:5.27.10-0ubuntu1
4:5.27.10-1ubuntu1
4:5.27.10-2ubuntu2
4:5.27.10-3ubuntu1
4:5.27.11-0ubuntu2
4:5.27.11-0ubuntu3
4:5.27.11-0ubuntu4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libcolorcorrect5",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libkfontinst5",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libkfontinstui5",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libkworkspace5-5",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libnotificationmanager1",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libplasma-geolocation-interface5",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libtaskmanager6",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "libweather-ion7",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "plasma-workspace",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "plasma-workspace-data",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "plasma-workspace-wayland",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        },
        {
            "binary_name": "sddm-theme-breeze",
            "binary_version": "4:5.27.11-0ubuntu4.1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6843-1.json"