PT-2025-29465 · Polkit+5 · Polkit+5
Mohamed Maatallah
·
Published
2025-07-14
·
Updated
2026-04-14
·
CVE-2025-7519
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
polkit (affected versions not specified)
Description:
A flaw exists in polkit where processing an XML policy with 32 or more nested elements in depth can trigger an out-of-bounds write. This can lead to a crash or unexpected behavior, with the possibility of arbitrary code execution. Exploitation requires a high-privilege account to place a malicious policy file.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Red Os
Suse
Ubuntu
Polkit