CVE-2009-4997

gnome-power-manager 2.27.92 - Unprotected User Data Exposure via Suspend/Hibernate Lock Bypass

Title source: llm
STIX 2.1

Description

gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: this issue exists because of a regression that followed a gnome-power-manager fix a few years earlier.

References (2)

Core 2

Scores

EPSS 0.0014
EPSS Percentile 34.3%

Details

CWE
CWE-264
Status published
Products (1)
gnome/power_manager 2.27.92
Published Sep 07, 2010
Tracked Since Feb 18, 2026