ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8762-1: polkit vulnerability

mediumAdvisoryimportance 28
AI summary · glm-5.3

Ubuntu warns polkit mishandles cookie input, letting a local attacker crash the daemon or possibly execute arbitrary code.

Ubuntu Security Notice USN-8762-1 addresses a vulnerability in polkit stemming from incorrect handling of cookie input. A local attacker could exploit the flaw to cause polkit to crash, producing a denial of service, or potentially execute arbitrary code. The notice indicates exploitation requires local access to the affected system.

  • Polkit incorrectly handles cookie input
  • Local attacker can cause a denial of service via crash
  • Arbitrary code execution is also possible
  • Requires local access; patch via Ubuntu package updates
Full article

It was discovered that polkit incorrectly handled cookie input. A local attacker could possibly use this issue to cause polkit to crash, resulting in a denial of service, or execute arbitrary code.

This source does not provide full text. Read it at ubuntu.com.