Impact
This vulnerability in PortProtonQt arises from an incorrect authorization check that lets any local user mount or unmount arbitrary filesystems and modify the system’s network configuration through NetworkManager. The core weakness is a lack of access control, identified as CWE-863.
Affected Systems
Linux‑Gaming PortProtonQt versions before commit 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, while the EPSS score of less than 1% shows that exploitation is currently unlikely. Because the flaw is local, an attacker must have an account on the target system to exploit it, and the issue is not included in the CISA KEV catalog. A standard user can mount filesystems and modify network settings, thereby gaining unauthorized local privileges.
OpenCVE Enrichment