USN-8762-1: polkit vulnerability
AI summary · glm-5.3
Ubuntu warns polkit mishandles cookie input, letting a local attacker crash the daemon or possibly execute arbitrary code.
Ubuntu Security Notice USN-8762-1 addresses a vulnerability in polkit stemming from incorrect handling of cookie input. A local attacker could exploit the flaw to cause polkit to crash, producing a denial of service, or potentially execute arbitrary code. The notice indicates exploitation requires local access to the affected system.
- Polkit incorrectly handles cookie input
- Local attacker can cause a denial of service via crash
- Arbitrary code execution is also possible
- Requires local access; patch via Ubuntu package updates
Full article
It was discovered that polkit incorrectly handled cookie input. A local attacker could possibly use this issue to cause polkit to crash, resulting in a denial of service, or execute arbitrary code.
This source does not provide full text. Read it at ubuntu.com.