[Git][security-tracker-team/security-tracker][master] Add CVE-2026-85498/policykit-1
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 6 08:00:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
560fbdff by Salvatore Bonaccorso at 2026-09-06T08:59:34+02:00
Add CVE-2026-85498/policykit-1
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,9 @@
+CVE-2026-85498 [Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]
+ - policykit-1 <unfixed>
+ [trixie] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)
+ [bookworm] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)
+ NOTE: Introduced with: https://github.com/polkit-org/polkit/commit/7e122c8a5120c2aae2d9d44a26796dc18f5b677c
+ NOTE: The fix for CVE-2026-4897 introduces th new stack buffer underflow issue.
CVE-2026-XXXX [tryton-server: Python code execution via uploaded templates]
- tryton-server 7.0.53-1
NOTE: https://discuss.tryton.org/t/security-release-for-issue-5160-and-14869/9266
@@ -133132,6 +133138,7 @@ CVE-2026-4897 (A flaw was found in polkit. A local user can exploit this by prov
NOTE: Fixed by: https://github.com/polkit-org/polkit/commit/7e122c8a5120c2aae2d9d44a26796dc18f5b677c
NOTE: Introduced with (part of the fixes for CVE-2015-4625):
NOTE: https://github.com/polkit-org/polkit/commit/ea544ffc18405237ccd95d28d7f45afef49aca17 (0.113)
+ NOTE: When fixing this, the fix will introduce the issue CVE-2026-85498
CVE-2026-4887 (A flaw was found in GIMP. This issue is a heap buffer over-read in GIM ...)
- gimp 3.2.0-1 (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/15960
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560fbdffde7407113e462ce06fb6f69950689f96
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/560fbdffde7407113e462ce06fb6f69950689f96
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/a805f9f6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list