RHSA-2026:59997: Moderate: polkit security update
Moderate: polkit security update
Other sources
The polkit packages provide a component for controlling system-wide privileges. This component provides a uniform and organized way for non-privileged processes to communicate with privileged ones.Security Fix(es): polkit: Polkit: Denial of Service via unbounded input processing through standard input (CVE-2026-4897) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/polkitto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-debuginfoto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-debugsourceto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-develto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-docsto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-libsto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkit-libs-debuginfoto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1 - Upgrade
Upgrade
redhat/polkitto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
redhat/polkit-debuginfoto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
redhat/polkit-debugsourceto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
redhat/polkit-develto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
redhat/polkit-libsto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
redhat/polkit-libs-debuginfoto a version that resolves this vulnerability.Fixed in 125-4.el10_2.1.aa - Upgrade
Upgrade
polkitto a version that resolves this vulnerability.Patch CVE-2026-4897
Event History
Frequently Asked Questions
What impact does this update address?
It addresses CVE-2026-4897, a denial-of-service issue in polkit caused by unbounded processing of standard input. Polkit controls system-wide privileges and mediates communication between non-privileged and privileged processes.
Which packages are included in the advisory?
The advisory lists polkit, polkit-debuginfo, polkit-debugsource, polkit-devel, polkit-libs, and polkit-libs-debuginfo. It also applies to the listed Red Hat Enterprise Linux ARM 64 and Power little-endian offerings.