{"id":9724,"date":"2026-01-08T10:04:03","date_gmt":"2026-01-08T10:04:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/08\/linux-battery-utility-flaw-lets-hackers-bypass-authentication-and-tamper-system-settings\/"},"modified":"2026-01-08T10:04:03","modified_gmt":"2026-01-08T10:04:03","slug":"linux-battery-utility-flaw-lets-hackers-bypass-authentication-and-tamper-system-settings","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/08\/linux-battery-utility-flaw-lets-hackers-bypass-authentication-and-tamper-system-settings\/","title":{"rendered":"Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings"},"content":{"rendered":"<p>    Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization.<\/p>\n<p>Security researchers from openSUSE identified a severe <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> bypass flaw in the power profiles daemon in TLP version 1.9.0, tracked as\u00a0CVE-2025-67859.<\/p>\n<p>The vulnerability exploits a race condition in the Polkit authorization mechanism, enabling unprivileged local users to gain unauthorized control over power management configurations.\u200b<\/p>\n<p>The flaw originated when TLP 1.9.0 introduced a new profiles daemon featuring a D-Bus API for controlling power settings.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th><strong>CVE ID<\/strong><\/th>\n<th><strong>Severity<\/strong><\/th>\n<th><strong>Attack Vector<\/strong><\/th>\n<th><strong>Impact<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-67859<\/td>\n<td>High<\/td>\n<td>Local<\/td>\n<td>Polkit Authentication Bypass<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>During a routine security review requested by SUSE\u2019s package maintainer, researchers discovered the <a href=\"https:\/\/cybersecuritynews.com\/linux-udisks-daemon-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">daemon<\/a> relied on Polkit\u2019s deprecated \u201cunix-process\u201d subject for authentication, a method known to be vulnerable since CVE-2013-4288.<\/p>\n<p>The vulnerability stems from the daemon\u2019s unsafe handling of process identification during authorization checks.<\/p>\n<p>When authenticating D-Bus clients, the system passes the caller\u2019s process ID (PID) to Polkit for verification.<\/p>\n<p>However, a race condition exists between when the PID is captured and when Polkit validates it, allowing attackers to substitute their process for one with higher privileges.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-attack-works\"><strong>How the Attack Works<\/strong><\/h2>\n<p>This authentication bypass grants local users complete control over TLP\u2019s power profile settings and logging configurations without requiring administrative credentials.<\/p>\n<p>While the attack requires local access, it poses significant risks in multi-user environments and shared systems.<\/p>\n<p>Beyond the primary authentication bypass, researchers identified three additional security issues:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th><strong>Issue Type<\/strong><\/th>\n<th><strong>Description<\/strong><\/th>\n<th><strong>Security Impact<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Predictable Cookie Values<\/strong><\/td>\n<td>Authentication tokens use sequential integers starting from zero, making them easy to guess.<\/td>\n<td>Attackers can <a href=\"https:\/\/cybersecuritynews.com\/infostealers-to-hijack-legitimate-business-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack<\/a> or interfere with power management holds created by other users.<\/td>\n<\/tr>\n<tr>\n<td><strong><a href=\"https:\/\/cybersecuritynews.com\/multiple-django-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Denial-of-Service<\/a> (DoS) Vulnerability<\/strong><\/td>\n<td>Unlimited profile holds can be created without authentication.<\/td>\n<td>System resources can be exhausted, leading to daemon crashes due to excessive memory usage.<\/td>\n<\/tr>\n<tr>\n<td><strong>Exception Handling Flaws<\/strong><\/td>\n<td>Improper input validation in the <code>ReleaseProfile<\/code> method allows malformed parameters.<\/td>\n<td>Unhandled exceptions are triggered, but the daemon continues running, risking instability.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The openSUSE security team <a href=\"https:\/\/security.opensuse.org\/2026\/01\/07\/tlp-polkit-authentication-bypass.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> all findings to TLP\u2019s upstream developer on December 16, 2025, initiating a coordinated disclosure process.<\/p>\n<p>After collaborative <a href=\"https:\/\/cybersecuritynews.com\/patch-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">patch<\/a> development over the holiday season, TLP version 1.9.1 was released on January 7, 2026, containing comprehensive fixes for all identified vulnerabilities.<\/p>\n<p>The patches implement robust <a href=\"https:\/\/cybersecuritynews.com\/poc-linux-privilege-escalation-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">D-Bus <\/a>\u201csystem bus name\u201d authentication, and replace predictable cookies with cryptographically random values.<\/p>\n<p>Enforce a maximum of 16 concurrent profile holds, and strengthen input validation throughout the daemon. Linux users running TLP should immediately upgrade to version 1.9.1 or later.<\/p>\n<p>System administrators managing multi-user environments should prioritize this update, as the vulnerability allows <a href=\"https:\/\/cybersecuritynews.com\/aws-sagemaker-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">privilege escalation<\/a> within power management subsystems.<\/p>\n<p>Distribution maintainers have been notified and are releasing updated packages through standard channels.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/linux-battery-utility-flaw\/\">Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/linux-battery-utility-flaw\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization. Security researchers from openSUSE identified a severe authentication bypass flaw in the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,406,131,648],"tags":[130],"class_list":["post-9724","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-linux","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9724"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9724"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9724\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}