UNKNOWNCVE-2026-25704
Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData
Platform
linux
Component
cosmic-greeter
Fixed in
https://github.com/pop-os/cosmic-greeter/pull/426
A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic. This issue affects cosmic-greeter before https://github.Com/pop-os/cosmic-greeter/pull/426.
How to fix
Actualice cosmic-greeter a la versión posterior a la corrección en https://github.com/pop-os/cosmic-greeter/pull/426. Esto solucionará la condición de carrera TOCTOU y evitará la escalada de privilegios.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free