Skip to content
Multiple Denial of Service Vulnerabilities in polkit Affect Ubuntu Systems

Multiple Denial of Service Vulnerabilities in polkit Affect Ubuntu Systems

First seen 14 Apr 2026, 15:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 15, 2026 at 15:22 UTC

Two significant vulnerabilities have been identified in polkit, affecting multiple Ubuntu releases, including 25.10, 24.04 LTS, and 22.04 LTS. The first vulnerability (CVE-2025-7519), discovered in July 2025, allows remote attackers to exploit improperly handled nested XML elements, potentially causing a denial of service if an administrator installs a malicious policy file. The second vulnerability (CVE-2026-4897), reported by Pavel Kohout in March 2026, involves the polkit-agent-helper-1 utility mishandling long input, which could also lead to a denial of service by local attackers. Both vulnerabilities pose a risk of system crashes, impacting the stability of affected systems. Users are advised to update their systems to mitigate these vulnerabilities. A standard system update will address these issues across the affected Ubuntu versions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 174d ago How this analysis works

Timeline

2025-07-14
CVE-2025-7519 published
2026-03-26
CVE-2026-4897 published
2026-04-14
Security advisory published for polkit vulnerabilities

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2025-7519 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed