CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility
ID: 20dc0fcf-7907-5af3-b047-93da635480e1
STIX ID: report--20dc0fcf-7907-5af3-b047-93da635480e1
Feed Name: securityonline.info
Threat Score
SUSE Security discovered multiple vulnerabilities in TLP 1.9.0: a Polkit authentication bypass in the new root‑privileged profiles daemon (CVE-2025-67859) that allows local users to issue privileged commands without authorization, and a resource-exhaustion weakness where local users can create unlimited profile holds (leading to DoS and unpredictable cookie values). Users are advised to upgrade to TLP 1.9.1 which restricts concurrent profile holds to mitigate the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
