|
|
Log in / Subscribe / Register

Debian alert DLA-4553-1 (policykit-1)

From:  Andreas Henriksson <andreas@fatal.se>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4553-1] policykit-1 security update
Date:  Wed, 29 Apr 2026 12:13:47 +0200
Message-ID:  <ephwx3w4tgwynhuosvc2t4t6r5esidzznx7yfsjia727qicycd@2zh3aybzdeba>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4553-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson April 29, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : policykit-1 Version : 0.105-31+deb11u2 CVE ID : CVE-2021-4115 CVE-2026-4897 Debian Bug : 1005784 1132234 Multiple vulnerabilities where identified in polkit, a toolkit for defining and handling the policy that allows unprivileged processes to speak to privileged processes. CVE-2021-4115 Kevin Backhouse of GitHub Security Lab (GHSL) found that there is a file descriptor leak in polkit, which can enable an unprivileged user to cause polkit to crash, due to file descriptor exhaustion. This could lead to currently ongoing authentication attempts to fail to authenticate resulting in a Denial of Service (DoS). CVE-2026-4897 Pavel Kohout, Aisle Research found that a local user provide a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system. For Debian 11 bullseye, these problems have been fixed in version 0.105-31+deb11u2. We recommend that you upgrade your policykit-1 packages. For the detailed security status of policykit-1 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/policykit-1 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmnx2dgACgkQC8R9xk0T UwYoyw//ZUStl46YproAOjDcrwyZWeQj7NPudXU0DL23iRDG6J9ICqT4QjwzyfsX 27PIUjZaSaoZyhWjRQuADTHxeyrVHBoOuijLmrcIThLOiU0ohk1xuqZEMw9Iy+3S AfnqnpIJrKwPY3g+6oWOWQHEfP5hg87bN+dwJRVT5Jd/GpN/SPOuFjZsuI8owYcb AphaS6NLwq4WhPpcGOyCTimeZzNceP0Mms8Gb6Gr0QRECcfOM64XQZSb2AvmRfHQ lODcfZDcxu2JzM/23ZNxig3yDB/I4x6k4QFLvVsypHLWz1w44mlmTd9koaIuKy1f K83Uv6VDrmeKUBxN1bvP/OsAl42RfQQnyOsVfZ8pGnB28fsenOVYRCc743XJYuoR nbL9A3TkEUAXq3Z8yrP9eB22vI4586JuWt1oUQcZA2l7fJqXidk9y+gkKBnebGru U+MKI2d/ieAsFl037RX3I3TJ+MlUuHui0zIyziFYf0k9qobyU8uvM7xiVsV3SEc/ zwVGGtf15Wzt3wjPj5uqbU4oCrN1dKu4jMJBnBBF1ONyawJifxs9973jn/kd25zW gVucqXvs4Jhp282FhJvM9l2+np+NKaHUDTO92FWc2u2KCLeJAQbfHqpCfeD0EvhS lkI0l+xvWhAgDwQQiGB+y1iPBHHpN4kyX3CvY1vqE5YSWG/cyBY= =CP/h -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds