Description
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
References (5)
Core 5
Core References
Issue Tracking, Patch x_refsource_confirm
https://git.gnome.org/browse/gnome-shell/commit/?id=a72dca361080ffc9f45ff90188a7cf013c3c4013
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0535.html
Issue Tracking, Patch x_refsource_confirm
https://git.gnome.org/browse/gnome-shell/commit/?id=f02b007337e61436aaa0e81a86ad707b6d277378
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.gnome.org/show_bug.cgi?id=737456
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2014/09/29/17
Scores
EPSS
0.0004
EPSS Percentile
13.7%
Details
CWE
CWE-399
Status
published
Products (5)
gnome/gnome-shell
3.14.0
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_hpc_node
7.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_workstation
7.0
Published
Dec 25, 2014
Tracked Since
Feb 18, 2026