Security readout for executives and security teams
Plain-English summary
CVE-2018-10380 affects kwallet-pam in KDE KWallet before 5.12.6. A local user could exploit a symlink handling flaw to take ownership of arbitrary files. This is mainly a workstation or Linux desktop risk, not a remote network-entry issue.
Executive priority
Prioritize patching managed Linux desktops and shared systems where untrusted local users may log in. Treat as lower urgency than remote code execution, but do not ignore it on multi-user environments.
Technical view
The source description identifies a local symlink attack in kwallet-pam before KDE KWallet 5.12.6 that can change ownership of arbitrary files. That can undermine file permissions and may support local privilege escalation depending on the targeted file and system configuration.
Likely exposure
Exposure is most likely on Linux desktops or servers with KDE KWallet kwallet-pam installed and enabled for PAM login flows, especially versions before 5.12.6 or unfixed distribution builds.
Exploitation context
The bundle does not show CISA KEV listing or cited active exploitation. The attack requires local user access. Public evidence is limited to vendor and distribution references, so internet-scale exploitation should not be assumed.
Researcher notes
The source bundle lacks CVSS, CWE, and detailed affected CPEs. Analysis is based on the CVE description, KDE fix references, KDE advisory, and Debian DSA-4200. Avoid assuming affected distributions beyond cited vendor evidence.
Mitigation direction
- Upgrade KDE KWallet kwallet-pam to 5.12.6 or a fixed distribution package.
- Apply Debian DSA-4200 updates where applicable.
- Check KDE and OS vendor advisories for supported fixed package names.
- Reduce unnecessary local shell or desktop accounts on affected systems.
Validation and detection
- Inventory systems with KDE KWallet or kwallet-pam installed.
- Verify package versions are 5.12.6 or vendor-fixed builds.
- Confirm PAM login configuration uses or does not use kwallet-pam.
- Check package changelogs for CVE-2018-10380 or referenced KDE fixes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-10380 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- DSA-4200CVE reference · vendor-advisory, x_refsource_DEBIAN
- https://commits.kde.org/kwallet-pam/99abc7fde21f40cc6da5feb6ee766cc46fcca1f8CVE reference · x_refsource_CONFIRM
- https://bugzilla.suse.com/show_bug.cgi?id=1090863CVE reference · x_refsource_CONFIRM
- https://commits.kde.org/kwallet-pam/01d4143fda5bddb6dca37b23304dc239a5fb38b5CVE reference · x_refsource_CONFIRM
- https://commits.kde.org/kwallet-pam/802f305d81f8771c4f4a8bd7fd0e368ffc6f9b3bCVE reference · x_refsource_CONFIRM
- https://commits.kde.org/kwallet-pam/2134dec85ce19d6378d03cddfae9e5e464cb24c0CVE reference · x_refsource_CONFIRM
- https://www.kde.org/info/security/advisory-20180503-1.txtCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
