---
id: CVE-2026-4897
title: A flaw was found in polkit
summary: >-
  A flaw was found in polkit. A local user can exploit this by providing a
  specially crafted, excessively long input to the `polkit-agent-helper-1`
  setuid binary via standard input (stdin). This unbounded input can lead to an
  out-of-memory…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: freedesktop
product: polkit
affected:
  - polkit
  - openshift_container_platform = 4.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
published: '2026-03-26'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T18:18:01.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4897'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:59997'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:66287'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-4897'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2451739'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4897.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-4897'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4897'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-28T02:23:56.266925Z'
epss: 0.00153
epssPercentile: 0.04829
ingestedAt: '2026-08-21T14:17:57.487Z'
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_baseos_v_10
  - hardened_images
---

## Overview

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.

## Affected

- `polkit`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:59997** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:59997)
- **RHSA-2026:66287** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66287)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4897.json)
