{"id":"AZL-81558","summary":"CVE-2026-4897 affecting package polkit for versions less than 123-4","details":"A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.","modified":"2026-09-21T05:34:22Z","published":"2026-03-26T15:16:43Z","upstream":["CVE-2026-4897"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4897"}],"affected":[{"package":{"name":"polkit","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/polkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"123-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81558.json"}}],"schema_version":"1.9.0"}