Описание
Security update for polkit
This update for polkit fixes the following issue:
- CVE-2026-4897: Fixed possible OOM condition via specially crafted input to
polkit-agent-helper-1(bsc#1260859).
Список пакетов
openSUSE Leap 16.0
libpolkit-agent-1-0-123-160000.3.1
libpolkit-gobject-1-0-123-160000.3.1
pkexec-123-160000.3.1
polkit-123-160000.3.1
polkit-devel-123-160000.3.1
polkit-doc-123-160000.3.1
typelib-1_0-Polkit-1_0-123-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1260859
- SUSE CVE CVE-2026-4897 page
Описание
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
Затронутые продукты
openSUSE Leap 16.0:libpolkit-agent-1-0-123-160000.3.1
openSUSE Leap 16.0:libpolkit-gobject-1-0-123-160000.3.1
openSUSE Leap 16.0:pkexec-123-160000.3.1
openSUSE Leap 16.0:polkit-123-160000.3.1
Ссылки
- CVE-2026-4897
- SUSE Bug 1260859