logo

Linux Battery Utility Vulnerability Allows Authentication Bypass and System Tampering 

ID: 42241768-f22e-569e-814a-c274aaf6fb4d

STIX ID: report--42241768-f22e-569e-814a-c274aaf6fb4d

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Divya

...
...

TLP 1.9.0's profiles daemon used a deprecated Polkit "unix-process" subject tied to caller PIDs, creating a race condition that permits local users to bypass authorization (CVE-2025-67859) and modify active power profiles and logging; related issues included predictable cookies, unhandled type errors, and unbounded profile holds. Upstream addressed these issues in TLP 1.9.1 (released Jan 7, 2026) by switching to the D-Bus system bus name for authorization, using random cookies, hardening type handling, and limiting simultaneous profile holds — users are advised to upgrade and restrict local D-Bus/power-management access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.