KDE Plasma Workspaces: Privilege Escalation A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation. plasma-workspace 2024-07-06 2024-07-06 933342 remote 5.27.11.1 5.27.11.1

KDE Plasma workspace is a widget based desktop environment designed to be fast and efficient.

Multiple vulnerabilities have been discovered in KDE Plasma Workspaces. Please review the CVE identifiers referenced below for details.

KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE based purely on the host, allowing all local connections. This allows another user on the same machine to gain access to the session manager. A well crafted client could use the session restore feature to execute arbitrary code as the user on the next boot.

There is no known workaround at this time.

All KDE Plasma Workspaces users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=kde-plasma/plasma-workspace-5.27.11.1"
CVE-2024-36041 graaff graaff