High severity7.0NVD Advisory· Published Mar 28, 2018· Updated Jun 17, 2026
CVE-2018-8885
CVE-2018-8885
Description
screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: =0.17.2
- cpe:2.3:a:canonical:screen-resolution-extra:0.17.2:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- usn.ubuntu.com/3607-1/nvdVendor Advisory
News mentions
0No linked articles in our index yet.