VDB

GCVE-110-MAGEIA-2024-214

GCVE-110-MAGEIA-2024-214
Advisory Published
Vulnetix · Advisory published June 7, 2024
KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE based purely on the host, allowing all local connections. This allows another user on the same machine to gain access to the session manager. A well crafted client could use the session restore feature to execute arbitrary code as the user on the next boot.

Affected Products

VendorProductVersionsPlatforms
Mageiallvm17-suite0 (affected), 17.0.6-2.7.mga9 (unaffected)
Mageiallvm19-suite0 (affected), 19.1.0-3.mga9 (unaffected)
Mageiaplasma-workspace0 (affected), 5.27.10-1.1.mga9 (unaffected), 0 (affected), 5.27.10-1.1.mga9 (unaffected)

Browse GCVE Records

74,108 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›