THREAT OPS › Threat News › LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038)
LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038)
<p>Posted by Matthias Gerstner on Aug 31</p>Hello list,<br /> <br /> this is a report about security issues in the LACT GPU control<br /> utilities. We also offer a rendered version of this report on our blog<br /> [1].<br /> <br /> Summary: LACT is a daemon and graphical UI for controlling GPUs on<br /> Linux. A review of a UNIX domain socket API uncovered a Polkit<br /> authentication bypass res
Indicators of compromise
- CVE-2026-75037cve
- CVE-2026-75038cve
Original source: https://seclists.org/oss-sec/2026/q3/626