HomeSecurityVulnerability in Linux battery tool allows changing system settings

Vulnerability in Linux battery tool allows changing system settings

A critical security vulnerability has been identified in TLP, a widely used battery optimization tool for Linux laptops, which allows local attackers to bypass authentication mechanisms and modify power management settings without permission.

See also: PoC exploit for CVE-2025-38352 vulnerability in Android/Linux kernel

Linux

openSUSE security researchers have discovered a serious authentication bypass vulnerability in the power profiles daemon of TLP version 1.9.0 , which has been documented as CVE-2025-67859 .

The vulnerability exploits a race condition in the Polkit, allowing unprivileged local users to gain unauthorized control over power management settings. The issue arose when TLP version 1.9.0 introduced a new power profile daemon with a D-Bus API for controlling power settings. During a regular security audit requested by the SUSE package maintainer, researchers found that the daemon relied on Polkit's deprecated "unix-process" authentication object, a method that has been vulnerable since CVE-2013-4288.

The vulnerability is due to the insecure way the daemon handles process identification during authorization checks. When authenticating D-Bus clients, the system passes the caller's process identifier (PID) to Polkit for verification.

See also: React2Shell vulnerability used to install Linux Backdoors

Vulnerability in Linux battery tool allows changing system settings

However, there is a timing gap between the moment the PID is recorded and the moment Polkit verifies it, which allows attackers to replace their process with one that has higher privileges.

The openSUSE security team disclosed all findings to the TLP lead developer on December 16, 2025, implementing a coordinated disclosure process.

After collaborating to develop fixes during the holiday season, TLP version 1.9.1, which includes full fixes for all identified vulnerabilities.

The fixes introduce a strong D-Bus authentication mechanism using "system bus name", replace predictable cookies with cryptographically random values, impose a maximum limit of 16 concurrent profile bindings, and strengthen input validation across the daemon. Linux users using TLP should upgrade to version 1.9.1 or later immediately.

See also: Cross-Platform Malware: How Trojans Exploit Windows, Linux, and Mac Simultaneously

Vulnerability in Linux battery tool allows changing system settings

System administrators in multi-user environments should prioritize this update, as the vulnerability allows privilege escalation in the power management subsystem. Distribution maintainers have already been notified and are making the updated packages available through official distribution channels.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS