diff options
| author | Praveen Kumar <praveen.kumar@windriver.com> | 2025-09-26 12:39:55 +0530 |
|---|---|---|
| committer | Anuj Mittal <anuj.mittal@intel.com> | 2025-10-06 16:00:16 +0800 |
| commit | 0d88144a27e2222366c8f3f2fcc50623f96afe7d (patch) | |
| tree | 44f1ef59b9b6cd89cc3608a985770633275eb0f4 /meta-multimedia | |
| parent | 8b5cb4ee987e55f8c4bbf7e626ebd7ae17c6d65c (diff) | |
| download | meta-openembedded-0d88144a27e2222366c8f3f2fcc50623f96afe7d.tar.gz | |
polkit: fix CVE-2025-7519
A flaw was found in polkit. When processing an XML policy with 32 or
more nested elements in depth, an out-of-bounds write can be triggered.
This issue can lead to a crash or other unexpected behavior, and
arbitrary code execution is not discarded. To exploit this flaw, a
high-privilege account is needed as it's required to place the
malicious policy file properly.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-7519
Upstream-patch:
https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245
Signed-off-by: Praveen Kumar <praveen.kumar@windriver.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
Diffstat (limited to 'meta-multimedia')
0 files changed, 0 insertions, 0 deletions
