After resume from suspend gdm reveals content from the desktop before the lock screen appears

Bug #1741248 reported by theghost
260
This bug affects 2 people
Affects Status Importance Assigned to Milestone
gdm
In Progress
Medium
gdm3 (Fedora)
In Progress
High
gdm3 (Ubuntu)
Triaged
High
Unassigned
gnome-shell (Ubuntu)
Triaged
High
Unassigned

Bug Description

This is a pretty severe bug as protected information are revealed for a short time before the lockscreen appears.

Steps to reproduce:

1. Suspend your computer (e.g. close laptop lid)
2. Resume your computer (e.g. open laptop lid)
3. See Desktop's content
4. Lockscreen appears

ProblemType: Bug
DistroRelease: Ubuntu 17.10
Package: gdm3 3.26.1-3ubuntu3
ProcVersionSignature: Ubuntu 4.13.0-21.24-generic 4.13.13
Uname: Linux 4.13.0-21-generic x86_64
ApportVersion: 2.20.7-0ubuntu3.7
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Thu Jan 4 12:59:20 2018
InstallationDate: Installed on 2017-09-18 (107 days ago)
InstallationMedia: Ubuntu 17.04 "Zesty Zapus" - Release amd64 (20170412)
ProcEnviron:
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
SourcePackage: gdm3
UpgradeStatus: Upgraded to artful on 2017-10-20 (75 days ago)
modified.conffile..etc.gdm3.custom.conf: [modified]
mtime.conffile..etc.gdm3.custom.conf: 2017-10-20T22:06:33.549836

Revision history for this message
theghost (theghost) wrote :
theghost (theghost)
information type: Private Security → Public
Changed in gdm:
importance: Unknown → Medium
status: Unknown → In Progress
Changed in gdm3 (Fedora):
importance: Unknown → High
status: Unknown → In Progress
tags: added: unlock
tags: added: resume
Changed in gdm3 (Ubuntu):
importance: Undecided → High
status: New → Triaged
information type: Public → Public Security
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Does this still happen on currently-supported releases? Thanks

Revision history for this message
theghost (theghost) wrote :

As I was hit by this on Ubuntu 17.10, I am struggling to find a way to reproduce the issue.

Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Also affects gnome-shell, since all the GUI code for gdm3 is provided by gnome-shell(!)

Changed in gnome-shell (Ubuntu):
status: New → Triaged
importance: Undecided → High
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Merged with bug 1532508.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.