CVE-2026-4897
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: secalert@redhat.com (Secondary)
Description
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
Affected (7)
Products: Freedesktop: Polkit · Redhat: Enterprise Linux, Openshift Container Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 10.0 | |
| Version 4.0 |
References (2)
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Timeline
No history available yet.