CVE-2026-4897: Polkit: polkit: denial of service via unbounded input processing through standard input
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4897?
CVE-2026-4897 is classified as a denial of service vulnerability affecting polkit.
How do I fix CVE-2026-4897?
To mitigate CVE-2026-4897, ensure that you update polkit to the latest version that addresses the vulnerability.
Who is affected by CVE-2026-4897?
CVE-2026-4897 affects local users of systems running polkit versions 0.113 and earlier.
What type of attack is CVE-2026-4897 associated with?
CVE-2026-4897 is associated with a denial of service attack through unbounded input processing.
Can CVE-2026-4897 be exploited remotely?
No, CVE-2026-4897 can only be exploited by a local user with access to the system.