Linuxsecurity Multiple Denial of Service Vulnerabilities in polkit Affect Ubuntu Systems
Article Content
- •Two critical vulnerabilities in polkit affect multiple Ubuntu versions.
- •CVE-2025-7519 allows remote denial of service via malicious XML policy files.
- •CVE-2026-4897 enables local denial of service through mishandled input.
Two significant vulnerabilities have been identified in polkit, affecting multiple Ubuntu releases, including 25.10, 24.04 LTS, and 22.04 LTS. The first vulnerability (CVE-2025-7519), discovered in July 2025, allows remote attackers to exploit improperly handled nested XML elements, potentially causing a denial of service if an administrator installs a malicious policy file. The second vulnerability (CVE-2026-4897), reported by Pavel Kohout in March 2026, involves the polkit-agent-helper-1 utility mishandling long input, which could also lead to a denial of service by local attackers. Both vulnerabilities pose a risk of system crashes, impacting the stability of affected systems. Users are advised to update their systems to mitigate these vulnerabilities. A standard system update will address these issues across the affected Ubuntu versions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2025-7519 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…