Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20925-1

Опубликовано: 08 июн. 2026
Источник: suse-cvrf

Описание

Security update for polkit

This update for polkit fixes the following issue:

  • CVE-2026-4897: Fixed possible OOM condition via specially crafted input to polkit-agent-helper-1 (bsc#1260859).

Список пакетов

openSUSE Leap 16.0
libpolkit-agent-1-0-123-160000.3.1
libpolkit-gobject-1-0-123-160000.3.1
pkexec-123-160000.3.1
polkit-123-160000.3.1
polkit-devel-123-160000.3.1
polkit-doc-123-160000.3.1
typelib-1_0-Polkit-1_0-123-160000.3.1

Описание

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.


Затронутые продукты
openSUSE Leap 16.0:libpolkit-agent-1-0-123-160000.3.1
openSUSE Leap 16.0:libpolkit-gobject-1-0-123-160000.3.1
openSUSE Leap 16.0:pkexec-123-160000.3.1
openSUSE Leap 16.0:polkit-123-160000.3.1

Ссылки