Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"

Дата публикации: 02-07-2026 11:51:00

A security disclosure has been made public today for a yet-to-be-patched arbitrary code execution vulnerability with the KDE Plasma desktop...

Основное содержимое страницы с новостью.

KDE

A security disclosure has been made public today for a yet-to-be-patched arbitrary code execution vulnerability with the KDE Plasma desktop.

Open-source developer Kimiblock discovered an arbitrary code execution exploit for Plasma that can break sandboxes. The issue was reported to upstream KDE developers via their security email address and reportedly ignored and unpatched in the latest Plasma 6.7 desktop. Following the typical 90 day embargo, the exploit including proof-of-concept code has been published.

KDE open new window

This web page outlines the arbitrary code execution and the possibility of malicious sandboxed apps such as via Flatpak could spawn arbitrary binaries on the host via Plasma's "Open New Window" action.

"While accidently middle clicking on the task bar (it would invoke “Open New Window” by default for a specific app), the app launched a new window as expected, yet it did not seem to remember my saved login credentials, nor did it use any of modified settings. Upon closer inspection, combining the PID obtained from KWin Debug Console and control groups + rootfs info from procfs, a complete sandbox escape has surfaced.
...
So it was clear, there is a complete sandbox escape when I accidently triggered a middle-click inside the virtual machine."

The issue is yet to be patched and with no follow-ups from the KDE security team, the proof of concept code and details were made public today following the 90 day window. All the details for those interested via the disclosure page.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1KDE Plasma 6.7.2 Brings Fix For Most Common KWin Crash, Better Chromium Video Playback0730-06-2026
2KDE Software Now Has Stable Btrfs Snapshot Integration With KIO-Snapshot 1.0013.2520-08-2026
3KDE Plasma 6.8 Lands Some Enticing Performance Optimizations This Week011.7322-08-2026
4XWayland 24.1.13 Released To Fix Two More Security Issues In The X.Org Codebase0508-07-2026
5Рассекречена новая версия Windows0503-07-2026
6KDE Linux Introduces "Developer Mode" Option, Easier Log Collection0501-07-2026
7New Linux Flaw Lets Attackers Escape VMs08.5713-07-2026
8Yet Another Linux Kernel Vulnerability Discovered08.3427-07-2026
9Another Logic Bug Found in Linux Kernel07.7401-06-2026
10Specially Crafted NTFS File-System Image Allows Root Access On Linux With NTFS3 Driver09.4822-08-2026

Классификация: Информация. Схожих патентов: 0. Схожих новостей: 10. Тональность: -2. Информативность: 7. Источник: www.phoronix.com.