A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade polkit-develUpgrade polkit-libs-debuginfoUpgrade polkit-debuginfoUpgrade polkitUpgrade polkit-debugsourceUpgrade polkit-docsUpgrade polkit-libs | Apr 14, 2026 | Mar 26, 2026 |
| Debian | — | Upgrade policykit-1 | May 3, 2026 | May 3, 2026 |
| Redhat_linux | — | Upgrade polkit-debuginfoUpgrade polkit-libsUpgrade polkit-libs-debuginfoUpgrade polkit-develNo solution existsUpgrade polkit-docsUpgrade polkit-debugsourceUpgrade polkit | Jul 17, 2026 | Mar 26, 2026 |
| Rocky_linux | — | Upgrade polkitUpgrade polkit-debugsourceUpgrade polkit-develUpgrade polkit-libs-debuginfoUpgrade polkit-debuginfoUpgrade polkit-libs | Aug 28, 2026 | Aug 26, 2026 |
| Suse | — | Upgrade libpolkit-gobject-1-0Upgrade libpolkit-gobject-1-0-32bitUpgrade polkitUpgrade typelib-1_0-Polkit-1_0Upgrade polkit-develUpgrade pkexecUpgrade libpolkit0Upgrade libpolkit-agent-1-0-32bitUpgrade libpolkit-agent-1-0Upgrade polkit-doc | Apr 21, 2026 | Apr 17, 2026 |
| Ubuntu | — | Upgrade policykit-1Upgrade polkitd | Apr 15, 2026 | Mar 26, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub