CVE-2026-25710

Description

A flaw was found in plasma-login-manager. A compromised plasmalogin service account could exploit this vulnerability to change the ownership of arbitrary files on the system. This could lead to privilege escalation, allowing an attacker to gain unauthorized control over system files and potentially the entire system.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

The `plasma-login-manager` component is typically part of desktop environments. If a system does not require a graphical desktop environment, consider removing packages associated with `plasma-login-manager` to reduce the attack surface. This action may remove desktop functionality.

Understanding the Weakness (CWE)

Confidentiality,Integrity

Technical Impact: Read Application Data; Modify Application Data

An attacker could read and modify data for which they do not have permissions to access directly.

Frequently Asked Questions

Want to get errata notifications? Sign up here.