CVE-2018-20781: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
  • Gnome Gnome Keyring: before 3.27.2 (fixed in 3.27.2)
  • Oracle ZFS Storage Appliance Kit: version 8.8 only

Published 2019-02-12. Last modified 2026-06-17.