LACT version 0.10.0 contains two local vulnerabilities affecting its root-privileged GPU-control daemon. CVE-2026-75037 is a Polkit authorization bypass: the daemon authenticated clients by PID alone, allowing an eligible local user to win a PID race and add profile-hook scripts that the daemon would execute as root. The issue was compounded by related UID-handling behavior in zbus_polkit.
CVE-2026-75038 affects LACT's unauthenticated debug-snapshot API, which used predictable names for files written under /tmp. The condition could permit local denial of service and, on insufficiently hardened systems, permission-related information exposure or file-clobbering attacks; upstream changed snapshot creation from File::create to File::create_new to prevent overwriting an existing path. Upstream remediated both flaws in LACT 0.10.1; administrators should upgrade and restrict untrusted local access to affected systems until patched.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
A public report detailed the two LACT local vulnerabilities, including the unauthenticated snapshot API's predictable /tmp archive names and missing exclusive-create protections. It noted that common protected_symlinks and protected_regular kernel settings mitigate much of the temporary-file attack surface.
CVE identifiers CVE-2026-75037 and CVE-2026-75038 were assigned to LACT's Polkit PID-race authorization bypass and predictable temporary snapshot-file vulnerability, respectively.
Researchers reported two local LACT flaws to the project: a PID-based Polkit authorization race tracked as CVE-2026-75037 and predictable snapshot-file creation tracked as CVE-2026-75038. The former could allow eligible local users to arrange root-executed profile hooks, while the latter could enable file-clobbering conditions on insufficiently hardened systems.
CVE-2020-8908 was published for Guava Files.createTempDir(), which creates world-readable temporary directories on Unix-like systems and can expose data to other local users. The issue affects Guava versions 1.0 before 32.0 and is rated Low with a CVSS v3.1 score of 3.3.
Upstream addressed both LACT vulnerabilities in version 0.10.1, including a related zbus_polkit UID-handling issue. The snapshot fix replaced File::create() with File::create_new(), preventing creation over existing paths and symlink-following at the predictable snapshot location.
Oracle released its July 2021 Critical Patch Update with 342 new security patches across its product families. The update addressed numerous remotely exploitable, unauthenticated flaws, including several rated CVSS 9.8 to 10.0.
Google deprecated Guava's Files.createTempDir() beginning with Guava 30.0 and documented its world-readable temporary-directory behavior rather than changing it. It recommended Java NIO Files.createTempDirectory() or a securely permissioned java.io.tmpdir location as mitigations.
Apache fixed the insecure temporary-directory creation and race-condition vulnerability CVE-2020-17521 in Groovy 2.4.21, 2.5.14, 3.0.7, and 4.0.0-alpha-2. The flaw could expose or modify sensitive data in shared temporary directories and, where executable code was stored there, enable local privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
security.opensuse.org
Open sourcegithub.com
Open sourcecve.org
Open sourceoracle.com
Open sourceissues.apache.org
Open sourcegithub.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.