suse · CVE-2017-8288

Quick triage

Priority: medium Published: 2021-05-30 13:55:59 UTC Updated: 2026-04-18 09:05:28 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-8288 severity moderate: SUSE including 61 source package names (gnome-extensions-40.5-1.1, gnome-extensions-41.4-150400.1.7, …), 102 product×package rows across 39 product lines (SUSE Linux Enterprise Desktop 12 SP2, SUSE Linux Enterprise Desktop 12 SP3, … (39 product lines)): Fixed 102.

Description:

gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.

cvelogic Threat Intelligence