CVE-2020-16126: Freedesktop Accountsservice

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.

Affected products

  • Freedesktop Accountsservice: before 0.6.55 (fixed in 0.6.55)

Published 2020-11-11. Last modified 2026-06-17.