CVE-2019-3820: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
  • Gnome Gnome-Shell: from 3.15.91, before 3.30.3 (fixed in 3.30.3); from 3.31.0, before 3.31.5 (fixed in 3.31.5)
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only

Published 2019-02-06. Last modified 2026-06-17.