[Git][security-tracker-team/security-tracker][master] Add CVE-2026-85498/policykit-1

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 08:00:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
560fbdff by Salvatore Bonaccorso at 2026-09-06T08:59:34+02:00
Add CVE-2026-85498/policykit-1

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2026-85498 [Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]
+	- policykit-1 <unfixed>
+	[trixie] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)
+	[bookworm] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)
+	NOTE: Introduced with: https://github.com/polkit-org/polkit/commit/7e122c8a5120c2aae2d9d44a26796dc18f5b677c
+	NOTE: The fix for CVE-2026-4897 introduces th new stack buffer underflow issue.
 CVE-2026-XXXX [tryton-server: Python code execution via uploaded templates]
 	- tryton-server 7.0.53-1
 	NOTE: https://discuss.tryton.org/t/security-release-for-issue-5160-and-14869/9266
@@ -133132,6 +133138,7 @@ CVE-2026-4897 (A flaw was found in polkit. A local user can exploit this by prov
 	NOTE: Fixed by: https://github.com/polkit-org/polkit/commit/7e122c8a5120c2aae2d9d44a26796dc18f5b677c
 	NOTE: Introduced with (part of the fixes for CVE-2015-4625):
 	NOTE: https://github.com/polkit-org/polkit/commit/ea544ffc18405237ccd95d28d7f45afef49aca17 (0.113)
+	NOTE: When fixing this, the fix will introduce the issue CVE-2026-85498
 CVE-2026-4887 (A flaw was found in GIMP. This issue is a heap buffer over-read in GIM ...)
 	- gimp 3.2.0-1 (unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/15960



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560fbdffde7407113e462ce06fb6f69950689f96

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560fbdffde7407113e462ce06fb6f69950689f96
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/a805f9f6/attachment.htm>


More information about the debian-security-tracker-commits mailing list