Description

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.

INFO

Published Date :

2026-03-26T14:56:05.943Z

Last Modified :

2026-03-30T15:53:47.626Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4897 vulnerability.

Vendors Products
Freedesktop
  • Polkit
Redhat
  • Enterprise Linux
  • Openshift
  • Openshift Container Platform

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact