UbuntuUpdates.org

Package "policykit-1"

Name: policykit-1

Description:

transitional package for polkitd and pkexec

Latest version: 0.105-33ubuntu0.1
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://www.freedesktop.org/wiki/Software/polkit/

Links


Download "policykit-1"


Other versions of "policykit-1" in Jammy

Repository Area Version
base main 0.105-33
security main 0.105-33ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.105-33ubuntu0.1 2026-04-14 12:08:06 UTC

  policykit-1 (0.105-33ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: OOB write via nested elements in XML policy
    - debian/patches/CVE-2025-7519.patch: check depth in
      src/polkitbackend/polkitbackendactionpool.c.
    - CVE-2025-7519
  * SECURITY UPDATE: DoS via excessively long input
    - debian/patches/CVE-2026-4897.patch: fix getline() string overflow in
      src/polkitagent/polkitagenthelperprivate.c.
    - CVE-2026-4897

 -- Marc Deslauriers <email address hidden> Fri, 10 Apr 2026 06:59:20 -0400

CVE-2025-7519 A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This iss
CVE-2026-4897 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set



About   -   Send Feedback to @ubuntu_updates