Known Vulnerabilities for Polkit by Freedesktop
Listed below are 2 of the newest known vulnerabilities associated with "Polkit" by "Freedesktop".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81686 json | openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-78422 json | Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bi... | Not Provided | 2026-08-31 | 2026-09-01 |
| CVE-2026-75037 json | Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue af... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-64324 json | In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partition l... | Not Provided | 2026-07-25 | 2026-08-17 |
| CVE-2026-41048 json | Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacke... | Not Provided | 2026-06-22 | 2026-07-07 |
| CVE-2026-41045 json | A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSna... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-15060 json | When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a d... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-4897 json | A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `po... | Not Provided | 2026-03-26 | 2026-09-10 |
| CVE-2025-7519 json | A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write ca... | Not Provided | 2025-07-14 | 2026-09-01 |
| CVE-2025-6019 json | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit pe... | Not Provided | 2025-06-19 | 2026-06-30 |