Permissions, Privileges, and Access Controls in gnome-shell - CVE-2023-43090
Published: September 21, 2023
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to certain key combinations remain active when the user session is locked. An attacker with physical access to device can activate the "single window mode" and "video" buttons in GNOME Screenshot utility by pressing twice the "V" then once the "W" key and record screen or make screenshots.
Affected software
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
Desktop Applications Module
openSUSE Leap
Anolis OS
Ubuntu
gnome-shell (Debian package)
gnome-shell
gnome-shell-doc
gnome-shell (Ubuntu package)
gnome-extensions
gnome-shell-debugsource
gnome-shell-calendar-debuginfo
gnome-shell-debuginfo
gnome-shell-devel
gnome-shell-calendar
gnome-shell-lang
How to mitigate CVE-2023-43090
gnome-shell (Debian package) - update to 43.6-1~deb12u2
gnome-shell - update to 44.1-2
gnome-shell-doc - update to 44.1-2
gnome-shell (Ubuntu package) - update to 44.3-0ubuntu1.1
gnome-extensions - update to 45.3-150600.5.6.1
gnome-shell - update to 45.3-150600.5.6.1
gnome-shell-debugsource - update to 45.3-150600.5.6.1
gnome-shell-calendar-debuginfo - update to 45.3-150600.5.6.1
gnome-shell-debuginfo - update to 45.3-150600.5.6.1
gnome-shell-devel - update to 45.3-150600.5.6.1
gnome-shell-calendar - update to 45.3-150600.5.6.1
gnome-shell-lang - update to 45.3-150600.5.6.1