(https://nvd.nist.gov/vuln/detail/CVE-2018-20839): systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled. references: https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993 @maintainer(s): Milestone for v243 release Gentoo Security Padawan (domhnall)
Commit is upstream in master: https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f
Waiting for this to be fixed. https://github.com/systemd/systemd/issues/12616
(In reply to Mike Gilbert from comment #2) > Waiting for this to be fixed. > > https://github.com/systemd/systemd/issues/12616 Fixed in https://github.com/systemd/systemd/pull/13109 ... which seems to have landed in v243. So tree is clean?