Bugfix Release
Power Profiles (tlp-pd)
- Fix polkit authentication bypass concerning profile and loglevel changes.
Resolves CVE-2025-67859: only 1.9.0 is vulnerable, 1.8.0 and older
versions are not affected. - Tighten polkit authentication.
- Limit the number of stacked profile holds (tlpctl launch) to 16.
Check out the full changelog for the remaining fixes!
For information regarding packaging, please refer to https://linrunner.de/tlp/developers/packaging.html.