CVE-2026-79617
PoC moderateIncorrect permissions in Pardus LightDM Greeter allow local privilege escalation
CVE-2026-79617 is an incorrect permission assignment for a critical resource (CWE-732) in the Pardus LightDM Greeter, the display-manager login component developed by TÜBİTAK BİLGEM for the Pardus Linux distribution. The flaw stems from incorrectly configured access controls, meaning a resource used by the greeter is not correctly permissioned; a local attacker with low privileges can trigger the issue without user interaction (AV:L/PR:L/UI:N). The high confidentiality and integrity impact (C:H/I:H) indicates the attacker can gain elevated, likely root-level, access on the local machine. Any system running Pardus LightDM Greeter before version 0.4.15 is affected, primarily Pardus desktop deployments. There is a public proof-of-concept reference (github.com/alpernae/CVE-2026-79617), but the issue is not yet in CISA KEV and no confirmed in-the-wild exploitation is reported.
What to do: Upgrade Pardus LightDM Greeter to version 0.4.15 or later via the Pardus package repositories (apt update && apt upgrade). Verify the installed greeter package version on affected machines, prioritize shared or multi-user systems where unprivileged users have local access, and review the public PoC repository (github.com/alpernae/CVE-2026-79617) for details on which resource permissions to check if patching is delayed.
| TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter | all versions before 0.4.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.
- Weakness
- CWE-732
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.