CVE-2026-25710
Description
A flaw was found in plasma-login-manager. A compromised plasmalogin service account could exploit this vulnerability to change the ownership of arbitrary files on the system. This could lead to privilege escalation, allowing an attacker to gain unauthorized control over system files and potentially the entire system.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
The `plasma-login-manager` component is typically part of desktop environments. If a system does not require a graphical desktop environment, consider removing packages associated with `plasma-login-manager` to reduce the attack surface. This action may remove desktop functionality.
Understanding the Weakness (CWE)
Confidentiality,Integrity
Technical Impact: Read Application Data; Modify Application Data
An attacker could read and modify data for which they do not have permissions to access directly.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.