Linux Battery Utility Vulnerability Allows Authentication Bypass and System Tampering
ID: 42241768-f22e-569e-814a-c274aaf6fb4d
STIX ID: report--42241768-f22e-569e-814a-c274aaf6fb4d
Feed Name: GBHackers
TLP 1.9.0's profiles daemon used a deprecated Polkit "unix-process" subject tied to caller PIDs, creating a race condition that permits local users to bypass authorization (CVE-2025-67859) and modify active power profiles and logging; related issues included predictable cookies, unhandled type errors, and unbounded profile holds. Upstream addressed these issues in TLP 1.9.1 (released Jan 7, 2026) by switching to the D-Bus system bus name for authorization, using random cookies, hardening type handling, and limiting simultaneous profile holds — users are advised to upgrade and restrict local D-Bus/power-management access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
