Linux battery utility TLP patched after authentication bypass flaw

A critical vulnerability in the TLP Linux power management tool has been fixed after researchers discovered it allowed local attackers to bypass authentication and alter system settings. The flaw, identified in version 1.9.0 and tracked as CVE-2025-67859, stemmed from a race condition in the Polkit mechanism. TLP developers released version 1.9.1 on January 7, 2026, addressing the issue following coordinated disclosure.

Security researchers from SUSE and openSUSE uncovered a severe authentication bypass in TLP version 1.9.0, a popular utility for optimizing laptop battery life on Linux systems. Tracked as CVE-2025-67859, the vulnerability exploited Polkit's deprecated "unix-process" subject, which relies on process IDs for authorization. This method, known to be susceptible to race conditions since CVE-2013-4288, allowed local unprivileged users to substitute their processes during authentication checks, gaining control over power profiles and daemon logging without administrative credentials.

The issue arose with the introduction of a new power daemon in TLP 1.9.0, featuring a D-Bus API for system settings. Researchers Matthias Gerstner and Filippo Bonazzi identified that attackers could exploit this to arbitrarily modify configurations in multi-user environments, posing risks of system tampering.

Additional flaws included predictable cookie values enabling unauthorized release of profile holds, unhandled exceptions from malformed requests, and unlimited profile holds that could lead to denial-of-service attacks. These collectively widened the attack surface.

On December 16, 2025, the researchers notified TLP's upstream developer, who responded promptly and provided patches within four days. After review, TLP 1.9.1 was released on January 7, 2026, implementing key fixes: switching to Polkit's secure "system bus name" subject, using cryptographically random cookie values, limiting concurrent profile holds to 16, and enhancing input validation.

Linux users and administrators are urged to update to version 1.9.1 or later via their distribution's package manager. This incident highlights the need for robust security in utilities handling privileged D-Bus operations, with the swift collaborative response exemplifying effective vulnerability management.

Makala yanayohusiana

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
Picha iliyoundwa na AI

Linux CopyFail exploit threatens root access amid Ubuntu outage

Imeripotiwa na AI Picha iliyoundwa na AI

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

Qualys researchers have identified a logic flaw in the Linux kernel that enables unprivileged local users to disclose sensitive files and execute arbitrary commands as root.

Imeripotiwa na AI

Researchers have identified a high-severity flaw in the Linux kernel that can allow untrusted users to gain root access. The issue stems from one incorrect character in the code.

Jumanne, 9. Mwezi wa sita 2026, 04:36:21

Single character triggers high-severity Linux kernel vulnerability

Jumatano, 13. Mwezi wa tano 2026, 20:07:02

New fragnesia linux kernel flaw disclosed

Jumatatu, 11. Mwezi wa tano 2026, 16:32:24

Linux kernel could gain kill switch for vulnerable functions

Jumamosi, 9. Mwezi wa tano 2026, 20:17:43

New dirty frag exploit grants root access on linux systems

Jumanne, 5. Mwezi wa tano 2026, 17:44:08

US government issues urgent CopyFail warning as Linux patches roll out

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa