ArchLinux: 202011-5: gdm: privilege escalation
Summary
gdm before 3.38.2 can be tricked into launching gnome-initial-setup, enabling an unprivileged user to create a new user account for themselves. The new account is a member of the sudo group, so this enables the unprivileged user to obtain admin privileges.
Resolution
Upgrade to 3.38.2-1.
# pacman -Syu "gdm>=3.38.2-1"
The problem has been fixed upstream in version 3.38.2.
References
https://gitlab.gnome.org/GNOME/gdm/-/issues/642 https://security.archlinux.org/CVE-2020-16125
Workaround
None.