Impact
The reported issue is a stack buffer underflow in the read_cookie() function of polkit. The vulnerability arises when the function processes cookie data, allowing memory corruption beyond the intended buffer. This weakness is classified as CWE‑125, which can expose confidential data or cause program crashes, impacting confidentiality and availability of the affected service.
Affected Systems
Polkit is a component commonly bundled with many Linux distributions. The CVE data does not specify affected versions or vendor patches; thus any system running a polkit build that includes the regression should be examined. The absence of explicit version information means users should verify the presence of the original fix historically applied to polkit.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall risk, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score is unavailable, so the probability of exploitation is unclear. Because the vulnerability occurs in a privileged user‑space component that processes cookie input, the likely attack vector is local or remote when an interface to untrusted input is exposed. No public exploitation evidence exists, so the risk is considered modest but warrants observation and version review.
OpenCVE Enrichment
Ubuntu USN