Description
No description is available for this CVE.
Published: n/a
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: Potential stack buffer underflow in polkit’s read_cookie() function
Action: Assess Impact
AI Analysis

Impact

The reported issue is a stack buffer underflow in the read_cookie() function of polkit. The vulnerability arises when the function processes cookie data, allowing memory corruption beyond the intended buffer. This weakness is classified as CWE‑125, which can expose confidential data or cause program crashes, impacting confidentiality and availability of the affected service.

Affected Systems

Polkit is a component commonly bundled with many Linux distributions. The CVE data does not specify affected versions or vendor patches; thus any system running a polkit build that includes the regression should be examined. The absence of explicit version information means users should verify the presence of the original fix historically applied to polkit.

Risk and Exploitability

The CVSS score of 3.5 indicates a low overall risk, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score is unavailable, so the probability of exploitation is unclear. Because the vulnerability occurs in a privileged user‑space component that processes cookie input, the likely attack vector is local or remote when an interface to untrusted input is exposed. No public exploitation evidence exists, so the risk is considered modest but warrants observation and version review.

Generated by OpenCVE AI on September 4, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Determine whether your installed polkit package contains the regression by reviewing its release notes or comparing its version against the latest official release that applies the original read_cookie() fix.
  • If the regression is present, upgrade to a recent polkit release that restores the original implementation; if no update is available, apply an upstream backport or manually patch the source code to address the stack buffer underflow.
  • As a temporary safeguard, restrict access to the polkit socket or disable features that invoke read_cookie() to limit exposure to untrusted input.

Generated by OpenCVE AI on September 4, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8762-1 polkit vulnerability
History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Polkit Project
Polkit Project polkit
Vendors & Products Polkit Project
Polkit Project polkit

Fri, 04 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title polkit: Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Subscriptions

Polkit Project Polkit
cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-04T00:00:00Z

Links: CVE-2026-85498 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:30:07Z

Weaknesses