A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-4897 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451739 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Apr 2026, 16:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat
Redhat enterprise Linux Freedesktop polkit Freedesktop Redhat openshift Container Platform |
|
| CPE | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:freedesktop:polkit:-:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-4897 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2451739 - Issue Tracking, Vendor Advisory |
30 Mar 2026, 13:26
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-26 15:16
Updated : 2026-04-21 16:29
NVD link : CVE-2026-4897
Mitre link : CVE-2026-4897
CVE.ORG link : CVE-2026-4897
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform
freedesktop
- polkit
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
