Package: swaylock
Version: 1.5-2
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <t...@security.debian.org>

Dear Maintainer,

I'm running Sway and use Swaylock to lock the screen when the laptop is asleep.
Sometimes when resuming from sleep, Swaylock will respond to the first keypress
of the password and display a spinner, but then freeze for about half a minute
and then just disappear and thereby allow access to Sway without the password
being entered.

I am not yet sure of the exact conditions that cause this issue but it's
happened >10 times so far on my system.

-- System Information:
Debian Release: 11.0
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-6-amd64 (SMP w/2 CPU threads)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages swaylock depends on:
ii  libc6               2.31-11
ii  libcairo2           1.16.0-5
ii  libgdk-pixbuf2.0-0  2.40.2-2
ii  libglib2.0-0        2.66.8-1
ii  libpam0g            1.4.0-7
ii  libwayland-client0  1.19.0-2
ii  libxkbcommon0       1.0.3-2

swaylock recommends no packages.

swaylock suggests no packages.

Reply via email to