CVE-2016-6866: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.
slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.
Affected products
- Fedoraproject Fedora: version 24 only; version 25 only
- Suckless Slock: up to and including 1.3
Published 2017-02-15. Last modified 2026-06-17.