CVE-2023-3297: Canonical Accountsservice
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
Affected products
- Canonical Accountsservice: before 23.13.9-2ubuntu2 (fixed in 23.13.9-2ubuntu2); before 22.08.8-1ubuntu7.1 (fixed in 22.08.8-1ubuntu7.1); before 22.07.5-2ubuntu1.4 (fixed in 22.07.5-2ubuntu1.4); before 0.6.55-0ubuntu12\~20.04.6 (fixed in 0.6.55-0ubuntu12\~20.04.6)
- Canonical Ubuntu Linux: version 20.04 only; version 22.04 only; version 22.10 only; version 23.04 only
Published 2023-09-01. Last modified 2026-06-17.