← Terug naar overzicht

CVE-2026-75037 describes an authentication bypass vulnerability in LACT (Linux AMD GPU Control Tool) affecting versions through 0.10.0. The flaw resides in the Polkit authentication mechanism, which relies on UnixProcessSubject and Peer PID for identity verification. This approach is susceptible to PID reuse attacks, allowing an attacker to bypass authentication checks. The vulnerability runs on Linux systems where LACT is installed and used for GPU management. A fix has been committed via commit d0478fe42c2219454e272f96b1cbd29ab37ee566 in the upstream GitHub repository. The issue was also tracked in the SUSE Bugzilla system under bug ID 1276480. Users are advised to update to a patched version beyond 0.10.0 to mitigate this risk.

Affected products

  • LACT (Linux AMD GPU Control Tool) 0.10.0 and earlier

Related CVE's

  • CVE-2026-75037

Categories

  • Identity & Access
  • Operating Systems