Executive brief
LACT is a Linux GPU configuration and monitoring tool. A symlink-following vulnerability allows a local attacker to cause a denial-of-service condition by manipulating symbolic links, potentially disrupting GPU monitoring and control functionality for legitimate users.
Technical details
This vulnerability is a UNIX symbolic link (symlink) following flaw in LACT, a GPU configuration and monitoring tool. The vulnerability allows a local attacker to exploit insecure file handling where the application follows symlinks without proper validation, potentially leading to unintended file access or modification. An attacker with local access can craft malicious symlinks in predictable locations to trigger a denial-of-service condition, preventing the application from functioning correctly. This attack requires local system access but no special privileges. The vulnerability affects LACT versions up to and including 0.10.0; patched versions or mitigations should be available in later releases.
Affected products
- ilya-zlobintsev LACT through 0.10.0
Timeline
- 2026-08-25: disclosed