logo

CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility

ID: 20dc0fcf-7907-5af3-b047-93da635480e1

STIX ID: report--20dc0fcf-7907-5af3-b047-93da635480e1

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

SUSE Security discovered multiple vulnerabilities in TLP 1.9.0: a Polkit authentication bypass in the new root‑privileged profiles daemon (CVE-2025-67859) that allows local users to issue privileged commands without authorization, and a resource-exhaustion weakness where local users can create unlimited profile holds (leading to DoS and unpredictable cookie values). Users are advised to upgrade to TLP 1.9.1 which restricts concurrent profile holds to mitigate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.