CVE-2018-19358General(gnome / gnome-keyring)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gnome-keyring

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gnome-keyring

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-27: 1Technical Details · 2026-01-27: 101-27
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ober@ooberober
    General

    @LukasHozda @KristianCsep In regards to storing encrypted secrets, some "modern" OSs have retarded implementations of this, namely gnome-keyring and kwallet, that will allow any software on D-Bus to access all of the keys. So be aware of fake security software. https://www.cve.org/CVERecord?id=CVE-2018-19358

    Post summary

    The tweet warns that gnome-keyring and kwallet expose stored secrets to any D-Bus application, referencing CVE-2018-19358, without evidence of active exploitation or a PoC, thus serving as a general advisory.

    0001084
    58 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomegnome-keyring---

Explore more