CVE-2018-14424: Use After Free
Last updated 18 August 2025
Other sources
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-14424.
What is the severity of CVE-2018-14424?
The severity of CVE-2018-14424 is high with a severity value of 7.8.
What is the affected software for CVE-2018-14424?
The affected software for CVE-2018-14424 is GDM version through 3.29.1 on Debian and Ubuntu.
How can a local attacker exploit CVE-2018-14424?
A local attacker can exploit CVE-2018-14424 by triggering a use-after-free vulnerability through specially crafted D-Bus method calls.
Where can I find more information about CVE-2018-14424?
You can find more information about CVE-2018-14424 in the references section of this vulnerability.