CVE-2018-8885: Canonical Screen-Resolution-Extra

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.

Affected products

  • Canonical Screen-Resolution-Extra: version 0.17.2 only
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only

Published 2018-03-28. Last modified 2026-06-17.