Junglewise Threat Intelligence

CVE-2026-59678: Linux-Gaming PortProtonQt incorrect authorization in Polkit rules

CVE-2026-59678 · Severity: info · CVSS 7.1 · Published 2026-07-23

Executive brief

PortProtonQt, a tool used to manage and launch games on Linux, contains a security flaw in how it handles system permissions. This vulnerability allows any local user on the system to bypass security prompts to mount or unmount storage drives and modify network settings. This could lead to unauthorized access to data on external drives or a disruption of the computer's internet and network connectivity.

Technical details

An Incorrect Authorization vulnerability (CWE-863) exists in the Polkit rules provided by PortProtonQt. The rules in 'ru.linux_gaming.PortProtonQt.rules' attempted to authorize actions by inspecting the command line of the calling process and its parent via 'ps' to check for the 'ppqtos' argument. Because process command lines can be easily spoofed by local users, an attacker can craft a process that satisfies this check. This allows any local user to perform privileged actions through NetworkManager and udisks2, including modifying system network settings and mounting or unmounting arbitrary file systems. The issue was fixed by requiring users to be part of a specific 'portprotonqt' group and have an active local session.

Affected products

  • Linux-Gaming PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe

Timeline

  • 2026-07-02: disclosed: Initial report to SUSE security team
  • 2026-07-17: patched: Upstream commit 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe released
  • 2026-07-23: advisory: CVE published to NVD

References