CVE-2014-7272: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
Affected products
- Fedoraproject Fedora: version 20 only; version 21 only
- Sddm Project Sddm: before 0.10.0 (fixed in 0.10.0)
Published 2018-03-08. Last modified 2026-06-17.