Skip to content

History / Security

Revisions

  • Add "Fixed in 0.9.3" advisory table (4 GHSAs, CVE pending)

    @mcdope mcdope committed Jul 2, 2026
  • Security.md: drop "(CVE pending)" labels from CVE table Advisories below CVSS 4.0 are not assigned a CVE by policy; show a dash in the CVE column instead of "(CVE pending)" and state the policy in the intro. Co-authored-by: Claude Opus 4.8 (1M context)

    @mcdope mcdope committed Jun 9, 2026
  • Fact-check pass: fix version annotations, add CVE/advisory section - Add a "Known CVEs and security advisories" section to Security.md listing all 28 published advisories grouped by fix version (0.8.7-0.9.2) with CVE/GHSA IDs, severity and CVSS, plus a note that further advisories are in preparation for the next release. - Correct version annotations: remote_desktop_check and the pamusb-conf --superuser flag landed in v0.9.0, not the non-existent v0.8.8. - Security.md: replace the stale "pamusb-conf has no --superuser flag / issue #337" note; the flag exists since v0.9.0. - Configuration.md: document the shipped default deny_remote service whitelist (gdm-password, lightdm, sddm, polkit-1, login, ...) and note that remote_desktop_check only applies when deny_remote is enabled. - Troubleshooting.md: match the real "XRDP session detected ()" log string and add xrdp to the RDP detection row. - Home.md: replace the long-dead KDM example with SDDM/LightDM. Co-authored-by: Claude Opus 4.8 (1M context)

    @mcdope mcdope committed Jun 9, 2026
  • [0.9.2] Add error log section to superuser device restriction docs Security.md had only a debug-mode output section. Since v0.9.2 (#399), pam_usb also emits a log_error (visible without debug mode) when all of a user's devices are excluded by the superuser filter. Align with the equivalent section already in Configuration.md.

    @mcdope mcdope committed May 23, 2026
  • [0.9.2] Remove per-device option limitation caveat, add version notes - Remove the "currently not applied" warning about -level options; per-device config is fixed in 0.9.2 (GHSA-chgp-j28w-mx9q, #398). - Update option precedence note to document scope (v0.9.2+). - Add v0.9.2 marker to superuser log_error behavior (#399). - Security.md: fix "in 0.9.1" → "since 0.9.1" for XDMCP mitigation note.

    @mcdope mcdope committed May 23, 2026
  • Updated Security (markdown)

    @mcdope mcdope committed May 20, 2026
  • Update XDMCP warning to reflect 0.9.1 PAM_RHOST fix (GHSA-w38v-cw9r-x9p6) The unconditional PAM_RHOST check in 0.9.1 partially mitigates the XDMCP bypass, but protection depends on the display manager correctly setting PAM_RHOST for XDMCP connections. Updated the warning to reflect the fix while making clear it is not a universal guarantee for all DMs.

    @mcdope mcdope committed May 20, 2026
  • Updated Security (markdown)

    @mcdope mcdope committed May 18, 2026
  • Add sudo device doc

    @mcdope mcdope committed May 4, 2026
  • Updated Security (markdown)

    @mcdope mcdope committed Jul 18, 2024
  • Updated Security (markdown)

    @mcdope mcdope committed Jul 17, 2024
  • Updated Security (markdown)

    @mcdope mcdope committed Aug 30, 2022
  • Remove polkit notice since so much is whitelisted by now....

    @mcdope mcdope committed May 27, 2022
  • Updated Security (markdown)

    @mcdope mcdope committed Oct 30, 2021
  • Updated Security (markdown)

    @mcdope mcdope committed Oct 30, 2021
  • Updated Security (markdown)

    @mcdope mcdope committed Oct 30, 2021
  • Updated Security (markdown)

    @mcdope mcdope committed Aug 31, 2021
  • create sec notices, related to #51

    @mcdope mcdope committed Aug 31, 2021