{"id":"DEBIAN-CVE-2026-4897","details":"A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.","modified":"2026-09-11T08:47:27.984132685Z","published":"2026-03-26T15:16:43.017Z","upstream":["CVE-2026-4897"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-4897"}],"affected":[{"package":{"name":"policykit-1","ecosystem":"Debian:12","purl":"pkg:deb/debian/policykit-1?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["122-3","122-4","123-1","123-2","123-3","124-1","124-2","124-3","125-1","125-2","126-1","126-2","127-1","127-2","127-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4897.json"}},{"package":{"name":"policykit-1","ecosystem":"Debian:13","purl":"pkg:deb/debian/policykit-1?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["126-2","127-1","127-2","127-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4897.json"}},{"package":{"name":"policykit-1","ecosystem":"Debian:14","purl":"pkg:deb/debian/policykit-1?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"127-3"}]}],"versions":["126-2","127-1","127-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4897.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}