CVE-2015-7496: High severity red hat fedora vulnerability
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.
Other sources
It was found that when running gnome session, user locks the machine (by pressing <super> + l), presses Escape and holds, gdm will crash causing segmentation fault.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=758032
Upstream patches:
https://git.gnome.org/browse/gdm/commit/?id=5ac2246 https://git.gnome.org/browse/gdm/commit/?id=05e5fc2
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7496?
CVE-2015-7496 has been classified as a medium severity vulnerability due to the potential for local bypass of security controls.
How do I fix CVE-2015-7496?
To fix CVE-2015-7496, upgrade GNOME Display Manager to version 3.19.2 or later.
Which systems are affected by CVE-2015-7496?
CVE-2015-7496 affects GNOME Display Manager versions prior to 3.19.2 and specific versions of Fedora 23.
What type of attack does CVE-2015-7496 allow?
CVE-2015-7496 allows physically proximate attackers to bypass the lock screen protection.
What happens when CVE-2015-7496 is exploited?
Exploitation of CVE-2015-7496 leads to a crash of the GNOME Display Manager resulting in a segmentation fault.