KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References:
- https://bugs.mageia.org/show_bug.cgi?id=24334
- https://kde.org/info/security/advisory-20190209-1.txt
- 6/core/kauth-5.42.0-1.1.mga6
Get the latest Linux and open source security news straight to your inbox.