CVE-2017-8900: Medium severity Lightdm Project Lightdm vulnerability
Last updated 25 August 2025
Other sources
LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8900?
CVE-2017-8900 is considered a medium severity vulnerability that allows unauthorized access to user home directories by bypassing AppArmor restrictions.
How do I fix CVE-2017-8900?
To remediate CVE-2017-8900, upgrade LightDM to version 1.26.0 or later.
What systems are affected by CVE-2017-8900?
CVE-2017-8900 affects LightDM versions up to 1.22.0 on Ubuntu 16.10 and Ubuntu 17.x when using systemd.
Who can exploit CVE-2017-8900?
CVE-2017-8900 can be exploited by physically proximate attackers who can establish a guest session.
What is the impact of CVE-2017-8900 on users?
The impact of CVE-2017-8900 allows attackers to access and view the home directories of other users, leading to potential data exposure.