Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 2 advisories

CVE-2026-4897

CVE-2026-4897: 2 tracked advisory records across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

2 advisories
  • Advisory severityMedium5.5

    Medium [CVE-2026-4897] Polkit: polkit: denial of service via unbounded input processing through standard input

    CVE-2026-4897Source published Source updated

    A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system. A moderate severity issue, a denial of service flaw exists in polkit where a local attacker can exhaust system memory. This vulnerability arises from the `polkit-agent-helper-1` setuid binary processing excessively long input via standard input without size limitations, leading to an out-of-memory condition. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Hardened Images
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    4 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • polkit-0:125-4.el10_2.1
    • polkit-main-127-5.1.hum1
    • RHSA-2026:59997
    • RHSA-2026:66287
    Mitigation guidance
    • Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
  • Advisory severityLow3.5

    Low [CVE-2026-4897 +1] Regression in CVE-2026-4897 fix (polkit read_cookie) - stack buffer underflow

    CVE-2026-85498Source published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow. Red Hat rates this low (CVSS 3.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:66287 with package polkit-main-127-5.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 7 more.

    Related products — impact not confirmed
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7
    • Red Hat Enterprise Linux 8

    7 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • polkit-main-127-5.1.hum1
    • RHSA-2026:66287
    Mitigation guidance
    • Mitigation for this issue is either not available or the currently available options do not meet the criteria for a mitigation as defined by the Red Hat Product Security team. This flaw remains subject to future review as new information becomes available. Exposure is limited: the defect is reachable only by a local/adjacent low-privileged user interacting with the polkit authentication agent and results at most in a crash (availability) of the affected process.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery