USN-6843-1: Plasma Workspace vulnerability

Publication date

26 June 2024

Overview

plasma-workspace would allow unintended access to the session manager.


Packages

Details

Fabian Vogt discovered that Plasma Workspace incorrectly handled
connections via ICE. A local attacker could possibly use this issue to
gain access to another user's session manager and execute arbitrary code.

Fabian Vogt discovered that Plasma Workspace incorrectly handled
connections via ICE. A local attacker could possibly use this issue to
gain access to another user's session manager and execute arbitrary code.

Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 noble plasma-workspace –  4:5.27.11-0ubuntu4.1
23.10 mantic plasma-workspace –  4:5.27.8-0ubuntu1.1
22.04 jammy plasma-workspace –  4:5.24.7-0ubuntu0.2
20.04 focal plasma-workspace –  4:5.18.8-0ubuntu0.2

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›