Bugzilla – Bug 118541
Vulnerability after resume from suspend
Last modified: 2005-09-23 08:09:57 UTC
In testing suspend to disk and resume, I've discovered that the console is locked AFTER resuming rather than BEFORE suspending. If resuming can be slowed, such as not allowing a throttled cpu to speed up, the unlock dialog can be delayed long enough to disclose information or execute commands. This is only locally exploitable. I have been able to reproduce this numerous times to reboot my laptop by bringing up a konsole, switching to root, and typing reboot before I was prompted to unlock the session.
known problem ... due to some design reasons we hopefully can address. Thanks! *** This bug has been marked as a duplicate of 115123 ***