CVE-2026-4897 aisle.com fix of unsanitized getline. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1774635f74 2026-04-13 00:49:53.479885+00:00 -------------------------------------------------------------------------------- Name : polkit Product : Fedora 42 Version : 126 Release : 3.fc42.2 URL : https://github.com/polkit-org/polkit Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. -------------------------------------------------------------------------------- Update Information: CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Jan Rybar - 126-3.2 - CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1774635f74' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2026-4897 aisle.com fix of unsanitized getline. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-387a47c82b 2026-04-02 01:05:52.796913+00:00 -------------------------------------------------------------------------------- Name : polkit Product : Fedora 43 Version : 126 Release : 6.fc43.2 URL : https://github.com/polkit-org/polkit Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. -------------------------------------------------------------------------------- Update Information: CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Jan Rybar - 126-6.2 - CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-387a47c82b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2026-4897 aisle.com fix of unsanitized getline. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-054c0e22d1 2026-03-31 00:16:35.926178+00:00 -------------------------------------------------------------------------------- Name : polkit Product : Fedora 44 Version : 127 Release : 2.fc44.2 URL : https://github.com/polkit-org/polkit Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. -------------------------------------------------------------------------------- Update Information: CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Jan Rybar - 127-2.2 - CVE-2026-4897 aisle.com fix of unsanitized getline -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-054c0e22d1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
backport of upstream commits 9dca831, 4e67dde. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0e9ef494fc 2026-03-10 00:53:06.309253+00:00 -------------------------------------------------------------------------------- Name : polkit Product : Fedora 43 Version : 126 Release : 6.fc43.1 URL : https://github.com/polkit-org/polkit Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. -------------------------------------------------------------------------------- Update Information: backport of upstream commits 9dca831, 4e67dde -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 4 2026 Jan Rybar - 126-6.1 - backport of upstream commits 9dca831, 4e67dde - PolkitSubject: avoid g_dbus warning -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0e9ef494fc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
config file permission change to increase security of polkitd. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-41bdb7dba8 2023-04-17 01:21:13.055008 --------------------------------------------------------------------------------Name : polkit Product : Fedora 38 Version : 122 Release : 3.fc38.1 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: config file permission change to increase security of polkitd --------------------------------------------------------------------------------ChangeLog: * Thu Mar 30 2023 Jan Rybar - 122-3.1 - config file permission change to increase security of polkitd - Resolves: bz#2182784 --------------------------------------------------------------------------------References: [ 1 ] Bug #2182784 - polkit: Privilege escalation from polkitd user https://bugzilla.redhat.com/show_bug.cgi?id=2182784 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-41bdb7dba8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
config file permission change to increase security of polkitd. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-4936e4e7f1 2023-04-13 01:53:04.374252 --------------------------------------------------------------------------------Name : polkit Product : Fedora 37 Version : 121 Release : 4.fc37.2 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: config file permission change to increase security of polkitd --------------------------------------------------------------------------------ChangeLog: * Tue Apr 11 2023 Jan Rybar - 122-3.2 - revert config file location * Thu Mar 30 2023 Jan Rybar - 122-3.1 - config file permission change to increase security of polkitd - Resolves: bz#2182784 --------------------------------------------------------------------------------References: [ 1 ] Bug #2182784 - polkit: Privilege escalation from polkitd user https://bugzilla.redhat.com/show_bug.cgi?id=2182784 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4936e4e7f1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-4115. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5e6d5fe680 2022-03-03 15:50:19.518051 --------------------------------------------------------------------------------Name : polkit Product : Fedora 34 Version : 0.117 Release : 3.fc34.3 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4115 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 16 2022 Jan Rybar - 0.117-3.3 - file descriptor exhaustion (GHSL-2021-077) - Resolves: CVE-2021-4115 --------------------------------------------------------------------------------References: [ 1 ] Bug #2007534 - CVE-2021-4115 polkit: file descriptor leak allows an unprivileged user to cause a crash https://bugzilla.redhat.com/show_bug.cgi?id=2007534 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5e6d5fe680' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-4034. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1acf1bb522 2022-01-26 23:39:02.085183 --------------------------------------------------------------------------------Name : polkit Product : Fedora 34 Version : 0.117 Release : 3.fc34.2 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4034 --------------------------------------------------------------------------------ChangeLog: * Tue Jan 25 2022 Jan Rybar - 0.117-3.2 - pkexec: argv overflow results in local privilege esc. - Resolves: CVE-2021-4034 --------------------------------------------------------------------------------References: [ 1 ] Bug #2025869 - CVE-2021-4034 polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector https://bugzilla.redhat.com/show_bug.cgi?id=2025869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1acf1bb522' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.