Unrated severityNVD Advisory· Published Oct 26, 2015· Updated May 6, 2026
CVE-2015-3218
CVE-2015-3218
Description
The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.fedoraproject.org/pipermail/package-announce/2015-July/161721.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-July/162294.htmlnvd
- lists.freedesktop.org/archives/polkit-devel/2015-July/000432.htmlnvd
- lists.freedesktop.org/archives/polkit-devel/2015-May/000420.htmlnvd
- lists.freedesktop.org/archives/polkit-devel/2015-May/000421.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-11/msg00042.htmlnvd
- www.securityfocus.com/bid/76086nvd
- www.securitytracker.com/id/1035023nvd
- usn.ubuntu.com/3717-1/nvd
News mentions
0No linked articles in our index yet.