Asymmetric denial of service In policykit-1
Description
The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 0.105-11 | ||
debian 11 | 0.105-11 | ||
debian 12 | 0.105-11 | ||
debian 13 | 0.105-11 | ||
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5.