Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
linrunner
linrunner
@linrunner@fosstodon.org  ·  activity timestamp last week

Version 1.9.1 of the #TLP #Linux #powersaving tool was released. It consists mainly of security fixes for #tlp-pd. For details, please refer to the publication by the #openSUSE Security Team.

https://github.com/linrunner/TLP/releases/tag/1.9.1
https://security.opensuse.org/2026/01/07/tlp-polkit-authentication-bypass.html

SUSE Security Team Blog

TLP: Polkit Authentication Bypass in Profiles Daemon in Version 1.9.0 (CVE-2025-67859)

TLP is a utility for saving laptop battery power when running Linux. In version 1.9.0 of TLP a profiles daemon has been added to the project, which provides a D-Bus interface for controlling different power profiles. An unsafe use of the Polkit authentication API in this daemon allows local users to bypass authorization and gain arbitrary control over power profiles and log level settings of TLP. While looking into the new daemon we also found a few other security issues in the area of local Denial-of-Service.
GitHub

Release 1.9.1 · linrunner/TLP

Bugfix Release Power Profiles (tlp-pd) Fix Polkit Authentication Bypass in Profiles Daemon in Version 1.9.0 (CVE-2025-67859) Version 1.8.0 and older are not affected Ensure that all processes tha...
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct