CVE-2020-16125: Gnome Display Manager
Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.
gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.
Affected products
- Gnome Gnome Display Manager: before 3.36.2 (fixed in 3.36.2); from 3.38.0, before 3.38.2 (fixed in 3.38.2)
Published 2020-11-10. Last modified 2026-06-17.