CVE-2026-85498

Public on 2026-09-05
Modified on 2026-09-05
Description
A flaw was found in polkit. A regression in the fix for CVE-2026-4897 introduced a stack buffer underflow (out-of-bounds read) in the read_cookie() function of the polkit-agent-helper-1 setuid helper. When an empty cookie is read from standard input, the string-length computation underflows and one byte is read outside the bounds of the stack buffer.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Mate-desktop1.x Extra mate-polkit Not Affected
Amazon Linux 2 - Core polkit Not Affected
Amazon Linux 2023 polkit Pending Fix
Amazon Linux 2027 Preview polkit Not Affected
Amazon Linux 2 - Core polkit-pkla-compat Not Affected
Amazon Linux 2023 polkit-pkla-compat Not Affected
Amazon Linux 2027 Preview polkit-pkla-compat Not Affected
Amazon Linux 2 - Core polkit-qt Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L