CVE-2018-8885: Canonical Screen-Resolution-Extra
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
Affected products
- Canonical Screen-Resolution-Extra: version 0.17.2 only
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only
Published 2018-03-28. Last modified 2026-06-17.